Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 5Objective 2

Identification of Malicious System and User Activity GCFA Practice Questions (Page 3)

Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
3concepts

Questions 11–15

  1. 11expert · hard

    A forensic team is investigating a server that was used to pivot into the network. They find that a user 'alice' logged on via SSH from an external IP, and shortly after, a process running as 'alice' executed a command that created a reverse shell to another internal server. Which correlation best explains the attack?

    Select an answer first
  2. 12foundation · easy

    During a forensic review of a compromised Windows workstation, an analyst observes a process named 'svchost.exe' running from the user's temporary folder. Which indicator of malicious system activity does this observation most directly represent?

    Select an answer first
  3. 13foundation · easy

    In a forensic review of authentication logs, an analyst finds that a standard user account successfully logged in at 3:00 AM, and shortly after, the account was added to the local Administrators group. Which malicious user activity does this sequence most directly indicate?

    Select an answer first
  4. 14application · medium

    An analyst is reviewing a user's activity logs. The user 'jdoe' normally works from 9 AM to 5 PM. The logs show that 'jdoe' logged in at 2 AM, accessed a database containing customer PII, and then used a file compression tool to create a ZIP file. The user's workstation was physically secured overnight. What is the most likely explanation?

    Select an answer first
  5. 15expert · hard

    An analyst is correlating events from a compromised server. The server's process logs show that 'svchost.exe' spawned 'powershell.exe' with a download cradle. The user activity logs show that a user account 'bjackson' was logged on at the time. The user's workstation was found to have a malicious macro-enabled document. Which conclusion is most defensible?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.