
GIAC Certified Forensic Analyst
Domain 5Objective 1
Identification of Normal System and User Activity GCFA Practice Questions (Page 2)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
3concepts
Questions 6–10
- 6
A company is establishing a baseline for user activity on a shared file server. The baseline shows that most users access files during business hours and use specific applications. One user, an accountant, typically accesses Excel files and PDFs. The analyst observes the accountant's account accessing a large number of executable files at 3:00 AM. What should the analyst do?
Select an answer first - 7
An analyst is reviewing user activity logs for a company that uses a VPN for remote access. The baseline shows that users typically connect from a specific set of IP addresses and use the VPN during business hours. The analyst notices a user connecting from a new IP address at 11:00 PM. What is the most appropriate next step?
Select an answer first - 8
A forensic analyst is examining a Windows server that runs a custom application. The baseline shows that the application typically makes 10–15 outbound connections to a specific database server on port 1433. During an investigation, the analyst finds the application making connections to a new IP address on port 1433, and the process name is the same. What is the most likely explanation?
Select an answer first - 9
An analyst is establishing a baseline for a server that runs a critical application. The server has been in production for a year, and the analyst has collected performance data for the past month. The analyst notices that the server's CPU usage has been gradually increasing over the past week, but it is still within the normal range. What should the analyst do?
Select an answer first - 10
A forensic analyst is examining a Linux server that runs a web application. The baseline shows that the server typically has 20–30 established outbound connections to database servers on port 5432, and CPU usage averages 20–30%. During an investigation, the analyst observes 150 outbound connections to an IP address on port 4444 and CPU usage at 95%. What is the most appropriate initial conclusion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.