Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 5Objective 2

Identification of Malicious System and User Activity GCFA Practice Questions (Page 2)

Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
3concepts

Questions 6–10

  1. 6expert · hard

    An analyst is correlating events from a web server and a database server. The web server logs show a series of SQL injection attempts from a specific IP, and the database server logs show a successful login from the same IP using a service account. The database logs also show a query that exports a large amount of data to a file. Which conclusion is most supported?

    Select an answer first
  2. 7expert · hard

    During an incident response, an analyst finds that a user's account was used to RDP into a server at 2:00 AM, and at the same time a process on that server spawned a child process that made an outbound connection to an IP address known for C2. The user claims they were asleep. Which conclusion is most defensible?

    Select an answer first
  3. 8expert · hard

    A forensic team is investigating a breach. System logs show a new service 'svchost_net' running from a non-standard path, and user logs show the 'admin' account was used to create a new local user 'backup' at the same time. The 'backup' user has no logon activity. Which conclusion is best supported by correlating these findings?

    Select an answer first
  4. 9foundation · easy

    An analyst correlates a user's login time with a system event showing that a process was launched from a suspicious path immediately after the login. What does this correlation most directly reveal?

    Select an answer first
  5. 10application · medium

    A user reports that their account has been locked out. The security logs show multiple failed logon attempts from various IP addresses over the past hour, followed by a successful logon from an IP in a foreign country. The user is currently at their desk and has not traveled. Which action should the analyst take first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.