Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 3

Analyzing Volatile Windows Event Artifacts GCFA Practice Questions (Page 2)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following is the default storage location for Windows Event Log files on a modern Windows system?

    Select an answer first
  2. 7foundation · easy

    Which of the following best describes the difference between classic Windows event logs and the modern Windows Event Log format?

    Select an answer first
  3. 8expert · hard

    You are analyzing a memory dump and find Event ID 4672 (special privileges assigned to new logon) for a user account that is not in the administrators group. You also find Event ID 4624 (logon) for the same user with a logon type of 2 (interactive) at the same time. Which conclusion is most consistent with these artifacts?

    Select an answer first
  4. 9application · medium

    During a forensic analysis of a memory dump, you extract Security event logs and find a series of event ID 4625 (logon failure) entries with LogonType 3 and a SubStatus of 0xC000006A (bad password). The failures occur every 2 seconds for 10 minutes from a single source IP, followed by a successful logon (event ID 4624) from the same IP. Which conclusion is most supported by this evidence?

    Select an answer first
  5. 10application · medium

    During an incident response, you have a memory dump from a compromised Windows 10 workstation. The on-disk event logs have been cleared, but you suspect that event records may still exist in the memory dump. Which approach is most likely to recover event records from the memory dump?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.