
GIAC Certified Forensic Analyst
Domain 2Objective 2
Analyzing Volatile Malicious Event Artifacts GCFA Practice Questions (Page 7)
Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
5concepts
Questions 31–35
- 31
An analyst is investigating a memory image from a system that is suspected of running a remote access trojan (RAT). The analyst finds a process 'svchost.exe' with an outbound connection to an external IP on port 8080. The process's path is 'C:\Windows\System32\svchost.exe' and its parent is 'services.exe'. Which additional artifacts would help confirm that this process is a RAT? Select all that apply.
Select an answer first - 32
Which memory forensics plugin is used to extract registry hives from a memory image for offline analysis?
Select an answer first - 33
An analyst is investigating a memory image from a system that was compromised. The analyst finds the following artifacts: (1) a process 'rundll32.exe' with a command line 'rundll32.exe C:\Users\Public\payload.dll,Start', (2) a registry key under 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' pointing to the same payload.dll, and (3) an outbound connection to an external IP on port 53 (DNS). The analyst needs to determine the malware's persistence and C2 mechanism. Which artifact is most critical for establishing persistence?
Select an answer first - 34
You are analyzing a memory image from a Windows workstation. You notice a process named 'notepad.exe' with a PID of 1234. You also notice that the process's memory contains a section that is marked executable and writable, and the section's name is 'MZ'. Which process analysis technique would best confirm that this is code injection?
Select an answer first - 35
Which registry hive, when extracted from memory, would contain the Run and RunOnce keys that are commonly used for malware persistence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.