
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 6)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 26–30
- 26
A forensic analyst is investigating a Windows workstation where a user reported slow performance. The analyst finds a process named 'svch0st.exe' running from C:\Users\Public\ with an open TCP connection to an external IP on port 4444. The user's account shows a successful logon at 3:00 AM, but the user denies being awake. Which combination of findings most strongly indicates coordinated malicious system and user activity?
Select an answer first - 27
A forensic analyst is correlating events from a compromised file server. The following were captured: (1) a user account 'jsmith' authenticated via RDP from an external IP at 02:00, (2) at 02:05, a process named 'winword.exe' spawned 'powershell.exe' with an encoded command, (3) at 02:10, the account 'jsmith' accessed a folder containing financial spreadsheets and copied files to a network share. The analyst must determine whether this is a coordinated attack or separate incidents. Which additional piece of evidence would most strongly support a coordinated attack?
Select an answer first - 28
A security analyst is reviewing authentication logs and sees that a standard user account 'jsmith' was added to the local Administrators group, and then a new scheduled task was created that runs a script to disable security software. Which user activity pattern does this represent?
Select an answer first - 29
A forensic analyst is investigating a Windows system where the user reports unusual behavior. The analyst finds a process named 'lsass.exe' running from C:\Users\Public\, and the same user account has recently been granted SeDebugPrivilege. Which finding is the strongest indicator of malicious activity?
Select an answer first - 30
An analyst is reviewing a Linux system's audit logs and notices a process making repeated 'connect()' system calls to the same external IP address on port 4444. Which type of malicious system activity does this pattern most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.