
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 2)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 6–10
- 6
An analyst is correlating events from a web server and a database server. The web server logs show a series of SQL injection attempts from a specific IP, and the database server logs show a successful login from the same IP using a service account. The database logs also show a query that exports a large amount of data to a file. Which conclusion is most supported?
Select an answer first - 7
During an incident response, an analyst finds that a user's account was used to RDP into a server at 2:00 AM, and at the same time a process on that server spawned a child process that made an outbound connection to an IP address known for C2. The user claims they were asleep. Which conclusion is most defensible?
Select an answer first - 8
A forensic team is investigating a breach. System logs show a new service 'svchost_net' running from a non-standard path, and user logs show the 'admin' account was used to create a new local user 'backup' at the same time. The 'backup' user has no logon activity. Which conclusion is best supported by correlating these findings?
Select an answer first - 9
An analyst correlates a user's login time with a system event showing that a process was launched from a suspicious path immediately after the login. What does this correlation most directly reveal?
Select an answer first - 10
A user reports that their account has been locked out. The security logs show multiple failed logon attempts from various IP addresses over the past hour, followed by a successful logon from an IP in a foreign country. The user is currently at their desk and has not traveled. Which action should the analyst take first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.