
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 3)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 11–15
- 11
A forensic team is investigating a server that was used to pivot into the network. They find that a user 'alice' logged on via SSH from an external IP, and shortly after, a process running as 'alice' executed a command that created a reverse shell to another internal server. Which correlation best explains the attack?
Select an answer first - 12
During a forensic review of a compromised Windows workstation, an analyst observes a process named 'svchost.exe' running from the user's temporary folder. Which indicator of malicious system activity does this observation most directly represent?
Select an answer first - 13
In a forensic review of authentication logs, an analyst finds that a standard user account successfully logged in at 3:00 AM, and shortly after, the account was added to the local Administrators group. Which malicious user activity does this sequence most directly indicate?
Select an answer first - 14
An analyst is reviewing a user's activity logs. The user 'jdoe' normally works from 9 AM to 5 PM. The logs show that 'jdoe' logged in at 2 AM, accessed a database containing customer PII, and then used a file compression tool to create a ZIP file. The user's workstation was physically secured overnight. What is the most likely explanation?
Select an answer first - 15
An analyst is correlating events from a compromised server. The server's process logs show that 'svchost.exe' spawned 'powershell.exe' with a download cradle. The user activity logs show that a user account 'bjackson' was logged on at the time. The user's workstation was found to have a malicious macro-enabled document. Which conclusion is most defensible?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.