
GIAC Certified Forensic Analyst
Domain 2Objective 2
Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 5)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 21–25
- 21
During memory forensics analysis of a compromised Windows system, which volatile artifact is most directly useful for identifying a process that is communicating with a known malicious IP address?
Select an answer first - 22
You are analyzing a memory image from a compromised Windows server. You find a process 'svchost.exe' with an outbound connection to an IP address on port 6667 (IRC). The process's path is 'C:\Windows\System32\svchost.exe'. Which additional volatile artifact would best help you determine if this is a botnet client?
Select an answer first - 23
An analyst extracts the NTUSER.DAT hive from a memory image and finds a value named 'Debugger' under 'HKCU\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\calc.exe' that points to 'C:\Users\Public\malware.exe'. What is the most likely purpose of this registry modification?
Select an answer first - 24
You are analyzing a memory image from a Windows host that is suspected of being infected with malware that uses a reflective DLL injection technique. Which volatile artifact would be most useful to identify the injected DLL?
Select an answer first - 25
A memory image shows a process 'lsass.exe' with an outbound connection to an external IP on port 443. The process's path is 'C:\Windows\System32\lsass.exe'. What is the most likely explanation for this network connection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.