
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 4)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 16–20
- 16
During an investigation, an analyst finds that a user's account was used to log in from a remote IP, and at the same time, a system log shows a new service was installed. Which conclusion does this correlation most directly support?
Select an answer first - 17
An analyst is investigating a server that is sending outbound traffic to an unusual IP address. The process list shows a service named 'Windows Update' running from C:\ProgramData\, and the service account has been granted 'Log on as a service' rights. Which finding is the strongest indicator of malicious system activity?
Select an answer first - 18
An analyst is investigating a server that runs a custom application. The application's process is named 'appsvc'. The analyst observes that 'appsvc' is making DNS queries to a domain that was recently registered and has no legitimate association with the company. Additionally, the process has a child process named 'cmd.exe' that is not part of the application's normal behavior. The analyst must decide whether to treat this as a compromise. Which factor would most strongly support a compromise conclusion?
Select an answer first - 19
An analyst is investigating a user who is suspected of stealing intellectual property. The logs show the user accessed a file server, copied a large number of design files, and then used a USB drive to transfer them to a personal laptop. Which action is the clearest indicator of malicious user activity?
Select an answer first - 20
An analyst is reviewing process execution logs on a server. They find that a process named 'rundll32.exe' executed with a command line that includes 'javascript:' and a long encoded string. The process's parent is a Microsoft Word document that was opened via email. What does this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.