
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 7)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 31–35
- 31
An analyst is investigating a potential data breach. The following events were found: (1) a user account 'mwilson' logged on to a file server at 3 AM, (2) the user's workstation had a keylogger installed, (3) at 3:15 AM, a process named 'powershell.exe' was used to download a file from a file-sharing site, (4) the file server logs show that 'mwilson' accessed a folder containing HR records and copied files to a USB drive. Which conclusion is most defensible?
Select an answer first - 32
An analyst is investigating a user account that was used to log into a server at 2 AM. The user denies any activity. The server logs show that the account was used to run 'regedit.exe' and modify the 'Run' registry key. What does this indicate?
Select an answer first - 33
An analyst is investigating a series of events on a network. The following were observed: (1) a user account 'tlee' logged into a workstation at 1 AM, (2) the workstation's process logs show that 'powershell.exe' was used to download a tool from a file-sharing site, (3) the tool was used to dump credentials from memory, (4) the credentials were then used to log into a domain controller. Which conclusion is most defensible?
Select an answer first - 34
An incident responder is correlating events from a compromised web server. The web server logs show a SQL injection attempt at 3:00 PM, and at 3:05 PM a new user account 'support' was created with admin privileges. At 3:10 PM, the 'support' account was used to upload a web shell. Which attack pattern is best supported?
Select an answer first - 35
During an incident response, you find that a standard user account recently executed 'whoami /priv' and 'net localgroup administrators' in quick succession, followed by a failed attempt to run 'psexec -s cmd.exe'. The account's logon session originated from a workstation that had been infected with a keylogger. What does this sequence most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.