Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 2

Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 6)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
5concepts

Questions 26–30

  1. 26foundation · easy

    Which memory forensics plugin or artifact would you use to list active TCP and UDP endpoints and associate them with the owning process ID?

    Select an answer first
  2. 27expert · hard · select all that apply

    An analyst is examining a memory image from a system that was infected with malware that uses a kernel driver for persistence. The analyst extracts the SYSTEM hive and finds a service named 'KernelSvc' with a start type of 0x1 (SYSTEM_START) and an image path of '\??\C:\Windows\System32\drivers\kernel.sys'. Which additional artifacts would help confirm that this driver is malicious? Select all that apply.

    Select an answer first
  3. 28application · medium

    An analyst is examining a memory image and uses a tool to list processes. The analyst notices that the process 'explorer.exe' has a memory region that is not backed by a file on disk and has RWX (read-write-execute) permissions. What should the analyst conclude from this finding?

    Select an answer first
  4. 29application · medium

    You are analyzing a memory image from a Windows host. You extract the SOFTWARE registry hive and find a new value under 'Microsoft\Windows\CurrentVersion\Run' that points to 'C:\Users\Public\update.exe'. You also find a process named 'update.exe' running. Which registry artifact would you examine next to understand the persistence mechanism?

    Select an answer first
  5. 30application · medium

    An analyst is examining a memory image from a system that is suspected of running keylogging malware. Which volatile artifact would be most directly relevant to confirming the keylogger's activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.