
GIAC Certified Forensic Analyst
The GIAC Certified Forensic Analyst (GCFA) certification validates your ability to collect and analyze data from computer systems to conduct formal incident investigations. It is designed for incident responders, threat hunters, and forensic analysts who must detect and eradicate advanced threats, including APTs and anti-forensic techniques. Earning GCFA proves you can handle complex digital forensic cases and serve as a vital line of defense for your organization.
417 practice questions · Updated 2026-07-30
5Domains
10Objectives
68Concepts
417Questions
GCFA Curriculum
Every domain, objective, and concept the GCFA exam measures.
- Incident Response Lifecycle
- Enterprise IR Team Roles
- IR Policy and Procedure
- IR Communication and Escalation
- Evidence Handling in Enterprise IR
- Enterprise IR Tools and Technologies
- Legal and Regulatory Considerations
- Business Continuity and Disaster Recovery
- Enterprise IR Metrics and Reporting
- Definition of Memory Forensics
- Volatile vs. Non-Volatile Data
- Memory Acquisition Overview
- Memory Analysis Goals
- Challenges in Memory Forensics
- Volatile Artifact Identification
- Process Analysis for Malware
- Network Connection Artifacts
- Registry Artifact Analysis
- Correlating Volatile Artifacts
- Event Log Fundamentals
- Event Log Acquisition
- Event Log Parsing from Memory
- Correlating Event Artifacts
- Analyzing Security Events
- Analyzing System and Application Events
- Timeline Construction
- Anti-Forensic Evasion Detection
- Timeline Forensics Fundamentals
- Timeline Creation Process
- Timeline Analysis Techniques
- Timeline Correlation and Interpretation
- Timeline Creation
- Timestamp Sources
- Timeline Correlation
- Timeline Analysis Techniques
- Artifact Interpretation
- NTFS File System Basics
- MFT and File Record Analysis
- NTFS Attribute Types
- Resident vs Non-Resident Data
- MFT Entry Number and Sequence Number
- NTFS Timestamps Analysis
- Alternate Data Streams (ADS)
- NTFS Compression and Encryption
- Deleted File Recovery in NTFS
- NTFS Journal ($LogFile) Analysis
- USN Journal Analysis
- NTFS $MFT and $Bitmap Analysis
- NTFS $Boot and $Volume Analysis
- NTFS $Extend and System Files
- Timeline Construction from NTFS
- NTFS Artifact Correlation
- Windows Artifact Fundamentals
- Registry Analysis
- Filesystem Artifacts
- Prefetch and Superfetch Analysis
- Event Log Analysis
- Shortcut (LNK) and Jump List Analysis
- Thumbnail and Cache Analysis
- Volume Shadow Copy Analysis
- Memory Artifact Correlation
- Timeline Construction
- Baseline System Activity
- Baseline User Activity
- Recognizing Anomalies
- Malicious System Activity Identification
- Malicious User Activity Identification
- Correlation of System and User Activity
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GCFA, so none is invented.