Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 5Objective 2

Identification of Malicious System and User Activity GCFA Practice Questions (Page 4)

Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
3concepts

Questions 16–20

  1. 16foundation · easy

    During an investigation, an analyst finds that a user's account was used to log in from a remote IP, and at the same time, a system log shows a new service was installed. Which conclusion does this correlation most directly support?

    Select an answer first
  2. 17application · medium

    An analyst is investigating a server that is sending outbound traffic to an unusual IP address. The process list shows a service named 'Windows Update' running from C:\ProgramData\, and the service account has been granted 'Log on as a service' rights. Which finding is the strongest indicator of malicious system activity?

    Select an answer first
  3. 18expert · hard

    An analyst is investigating a server that runs a custom application. The application's process is named 'appsvc'. The analyst observes that 'appsvc' is making DNS queries to a domain that was recently registered and has no legitimate association with the company. Additionally, the process has a child process named 'cmd.exe' that is not part of the application's normal behavior. The analyst must decide whether to treat this as a compromise. Which factor would most strongly support a compromise conclusion?

    Select an answer first
  4. 19application · medium

    An analyst is investigating a user who is suspected of stealing intellectual property. The logs show the user accessed a file server, copied a large number of design files, and then used a USB drive to transfer them to a personal laptop. Which action is the clearest indicator of malicious user activity?

    Select an answer first
  5. 20application · medium

    An analyst is reviewing process execution logs on a server. They find that a process named 'rundll32.exe' executed with a command line that includes 'javascript:' and a long encoded string. The process's parent is a Microsoft Word document that was opened via email. What does this indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.