Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 2Objective 3

Analyzing Volatile Windows Event Artifacts GCFA Practice Questions (Page 5)

Part of the Memory Forensics domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~20–35 in this domain), expect 7–12 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
8concepts

Questions 21–25

  1. 21application · medium

    You are analyzing a memory dump and find Event ID 4625 (failed logon) with a logon type of 3 (network) from an IP address that has attempted logons multiple times. Which additional event log record would best help you determine if this is a brute-force attack?

    Select an answer first
  2. 22application · medium

    During an incident response, you acquire a memory dump from a compromised Windows 10 workstation. Using Volatility 3, you extract event log records from memory. You find a series of Security event ID 4624 (logon) entries with LogonType 3, followed by event ID 4672 (special privileges assigned) for the same account. The user denies having accessed the server at that time. Which additional memory artifact would best corroborate that these logon events were network-based and not local console access?

    Select an answer first
  3. 23foundation · easy

    What is the primary purpose of constructing a timeline from parsed event logs?

    Select an answer first
  4. 24foundation · easy

    Which of the following is a required component of a parsed event log record that provides the time the event occurred?

    Select an answer first
  5. 25application · medium

    You are analyzing a memory dump from a server that was compromised. You find an event log record with Event ID 4624 (successful logon) showing a logon type of 3 (network) from an IP address that is not in the allowed list. Which additional memory artifact would best help you determine whether this logon led to malicious activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.