
GIAC Certified Forensic Analyst
Domain 2Objective 2
Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 6)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 26–30
- 26
Which memory forensics plugin or artifact would you use to list active TCP and UDP endpoints and associate them with the owning process ID?
Select an answer first - 27
An analyst is examining a memory image from a system that was infected with malware that uses a kernel driver for persistence. The analyst extracts the SYSTEM hive and finds a service named 'KernelSvc' with a start type of 0x1 (SYSTEM_START) and an image path of '\??\C:\Windows\System32\drivers\kernel.sys'. Which additional artifacts would help confirm that this driver is malicious? Select all that apply.
Select an answer first - 28
An analyst is examining a memory image and uses a tool to list processes. The analyst notices that the process 'explorer.exe' has a memory region that is not backed by a file on disk and has RWX (read-write-execute) permissions. What should the analyst conclude from this finding?
Select an answer first - 29
You are analyzing a memory image from a Windows host. You extract the SOFTWARE registry hive and find a new value under 'Microsoft\Windows\CurrentVersion\Run' that points to 'C:\Users\Public\update.exe'. You also find a process named 'update.exe' running. Which registry artifact would you examine next to understand the persistence mechanism?
Select an answer first - 30
An analyst is examining a memory image from a system that is suspected of running keylogging malware. Which volatile artifact would be most directly relevant to confirming the keylogger's activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.