
GIAC Certified Forensic Analyst
Domain 5Objective 1
Identification of Normal System and User Activity GCFA Practice Questions (Page 1)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
3concepts
Questions 1–5
- 1
A forensic analyst is investigating a potential insider threat. The company has a 24/7 operations team, and the analyst has established baselines for both system and user activity. The analyst notices that a user who works the night shift (11 PM–7 AM) has been logging in during the day shift (9 AM–5 PM) for the past three days. The user's job role does not require cross-shift work. Additionally, the user's workstation has been making outbound connections to a file-sharing website during these daytime logins. What is the most likely conclusion?
Select an answer first - 2
A security team is establishing a baseline for a Windows file server that hosts shared documents. They plan to monitor process creation, network connections, and performance counters. Which approach best establishes a meaningful baseline for detecting anomalies?
Select an answer first - 3
A forensic analyst is reviewing a Windows 10 workstation's event logs and process creation data after a suspected malware infection. The user is a graphic designer who works 9 AM to 5 PM. The analyst notices a process named 'svchost.exe' spawning 'cmd.exe' at 2:15 AM, and the user's account logged in at 2:14 AM. The analyst checks the baseline and finds that the user never logs in outside work hours. Which conclusion is most justified?
Select an answer first - 4
A forensic analyst is investigating a potential intrusion on a web server. The baseline shows that the server typically maintains 50–80 outbound connections, mostly to update repositories and monitoring services. During the investigation, the analyst observes 500 outbound connections to a single IP address on port 443. What does this indicate?
Select an answer first - 5
A forensic analyst is establishing a baseline for a Linux server that runs a web application. The baseline should include process activity, network connections, and system performance. Which tool or method is most appropriate for collecting this data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.