Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 3

Analyzing Volatile Windows Event Artifacts GCFA Practice Questions (Page 1)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 1–5

  1. 1expert · hard

    You are investigating a privilege escalation incident. From a memory dump, you extract Security event logs showing event ID 4672 (special privileges assigned) for a standard user account at 10:00:00. You also find that the user's token in memory has been modified to include the SeDebugPrivilege. The user account is not a member of any administrative group. Which conclusion is most supported?

    Select an answer first
  2. 2expert · hard

    You have a memory dump from a system where the on-disk event logs have been securely deleted using a disk-wiping tool. You need to recover event log data. Which approach is most likely to yield useful evidence?

    Select an answer first
  3. 3application · medium

    You are investigating a system where a user reported that an application crashed repeatedly. In the memory dump, you find Event ID 1000 (Application Error) from the Application log. Which additional event log record would best help you determine the root cause of the crash?

    Select an answer first
  4. 4foundation · easy

    When correlating event log entries with other memory artifacts, which of the following is most useful for linking a user's activity to a specific process?

    Select an answer first
  5. 5expert · hard

    You are analyzing a memory dump and find that the Security event log contains Event ID 1102 (Security log cleared) at 14:00:00. However, you also find Event ID 4624 (logon) records with timestamps after 14:00:00. What is the most likely explanation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.