
GIAC Certified Forensic Analyst
Domain 2Objective 2
Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 3)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 11–15
- 11
Which memory forensics technique is specifically designed to detect a process that has been hidden from the active process list by kernel-level rootkit manipulation?
Select an answer first - 12
When correlating volatile artifacts to reconstruct a malicious event, which combination of artifacts is most effective for establishing the initial infection vector?
Select an answer first - 13
Which volatile artifact, when extracted from a memory image, would be most useful for identifying a persistence mechanism that runs a malicious command at every system startup?
Select an answer first - 14
You are analyzing a memory image from a compromised web server. You find a process 'w3wp.exe' that has a child process 'cmd.exe' with the command line 'cmd.exe /c whoami'. You also see an outbound TCP connection from 'cmd.exe' to an internal IP on port 445. The server's firewall logs show that the internal IP is a file server. Which conclusion is best supported by correlating these volatile artifacts?
Select an answer first - 15
A forensic analyst is examining a memory image from a compromised Windows workstation. The analyst runs a process listing and notices a process named 'svchost.exe' with a parent process of 'cmd.exe'. The process path is 'C:\Users\Public\svchost.exe'. Which volatile artifact should the analyst prioritize for further investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.