Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 2

Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 3)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts

Questions 11–15

  1. 11foundation · easy

    Which memory forensics technique is specifically designed to detect a process that has been hidden from the active process list by kernel-level rootkit manipulation?

    Select an answer first
  2. 12foundation · easy

    When correlating volatile artifacts to reconstruct a malicious event, which combination of artifacts is most effective for establishing the initial infection vector?

    Select an answer first
  3. 13foundation · easy

    Which volatile artifact, when extracted from a memory image, would be most useful for identifying a persistence mechanism that runs a malicious command at every system startup?

    Select an answer first
  4. 14expert · hard

    You are analyzing a memory image from a compromised web server. You find a process 'w3wp.exe' that has a child process 'cmd.exe' with the command line 'cmd.exe /c whoami'. You also see an outbound TCP connection from 'cmd.exe' to an internal IP on port 445. The server's firewall logs show that the internal IP is a file server. Which conclusion is best supported by correlating these volatile artifacts?

    Select an answer first
  5. 15application · medium

    A forensic analyst is examining a memory image from a compromised Windows workstation. The analyst runs a process listing and notices a process named 'svchost.exe' with a parent process of 'cmd.exe'. The process path is 'C:\Users\Public\svchost.exe'. Which volatile artifact should the analyst prioritize for further investigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.