
GIAC Certified Forensic Analyst
Domain 2Objective 2
Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 2)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 6–10
- 6
When analyzing network connection artifacts in memory, which field is most important for correlating a connection to a specific malicious process?
Select an answer first - 7
A forensic analyst is reconstructing the timeline of a malware infection from a memory image. The analyst finds the following artifacts: (1) a process 'malware.exe' started at 10:00, (2) an outbound connection to an external IP at 10:05, (3) a registry run key created at 10:10, and (4) a file 'C:\Users\Public\payload.dll' created at 10:15. Which sequence best represents the likely order of events?
Select an answer first - 8
A forensic analyst is examining a memory image from a server that is suspected of being used as a botnet node. The analyst needs to identify volatile artifacts that would indicate the botnet's presence and activity. Which of the following artifacts should the analyst prioritize? Select all that apply.
Select an answer first - 9
You are analyzing a memory image from a compromised domain controller. You find a process 'spoolsv.exe' with a suspicious memory section that contains a PE header. You also find a registry key under 'HKLM\SYSTEM\CurrentControlSet\Services' that points to a DLL in 'C:\Windows\System32\spoolsv.dll'. The process has an outbound connection to an external IP on port 443. Which correlation of volatile artifacts best indicates the attack vector and persistence?
Select an answer first - 10
You are analyzing a memory image from a Windows host. You extract the SYSTEM registry hive and find a new service named 'LegitSvc' with a start type of 0 (SERVICE_BOOT_START) and an image path of 'C:\ProgramData\LegitSvc.exe'. You also find a network connection from a process with the same name to an external IP. Which registry artifact would you also examine to understand the service's behavior and persistence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.