Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 2

Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 5)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts

Questions 21–25

  1. 21foundation · easy

    During memory forensics analysis of a compromised Windows system, which volatile artifact is most directly useful for identifying a process that is communicating with a known malicious IP address?

    Select an answer first
  2. 22application · medium

    You are analyzing a memory image from a compromised Windows server. You find a process 'svchost.exe' with an outbound connection to an IP address on port 6667 (IRC). The process's path is 'C:\Windows\System32\svchost.exe'. Which additional volatile artifact would best help you determine if this is a botnet client?

    Select an answer first
  3. 23application · medium

    An analyst extracts the NTUSER.DAT hive from a memory image and finds a value named 'Debugger' under 'HKCU\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\calc.exe' that points to 'C:\Users\Public\malware.exe'. What is the most likely purpose of this registry modification?

    Select an answer first
  4. 24application · medium

    You are analyzing a memory image from a Windows host that is suspected of being infected with malware that uses a reflective DLL injection technique. Which volatile artifact would be most useful to identify the injected DLL?

    Select an answer first
  5. 25application · medium

    A memory image shows a process 'lsass.exe' with an outbound connection to an external IP on port 443. The process's path is 'C:\Windows\System32\lsass.exe'. What is the most likely explanation for this network connection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.