
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 1)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 1–5
- 1
An analyst is reviewing a user's activity after a suspected breach. The logs show the user accessed a database, exported a large CSV file, and then emailed it to a personal address. Which action is the clearest indicator of malicious user activity?
Select an answer first - 2
An analyst is examining a Linux server that appears to be running a cryptocurrency miner. The process list shows 'kworker' processes with high CPU usage, and the network connections show outbound connections to a known mining pool. Which additional finding would most strongly confirm malicious system activity?
Select an answer first - 3
A forensic analyst is examining a Linux system. They find a process named 'kworker' that is writing to /tmp/.ICE-unix/... and making connections to an external IP. The analyst knows that kworker is a kernel thread and should not have network connections. What does this indicate?
Select an answer first - 4
A user's account shows a successful logon from a workstation that was decommissioned two weeks ago. The user is currently on vacation. The security team suspects credential theft. Which additional evidence would most strongly confirm malicious user activity?
Select an answer first - 5
A user's account shows a successful logon at 2:00 AM from a foreign country, followed by a change to the user's password, and then access to a sensitive database. Which pattern of malicious user activity does this represent?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.