
GIAC Certified Forensic Analyst
Domain 5Objective 1
Identification of Normal System and User Activity GCFA Practice Questions (Page 4)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
3concepts
Questions 16–20
- 16
Which of the following data sources is most commonly used to establish a baseline of normal network connections for a host?
Select an answer first - 17
A forensic analyst is establishing a baseline for a critical production server. The server runs a batch processing job every night that consumes significant CPU and memory. The analyst needs to distinguish between normal batch processing and potential malicious activity. Which approach is most effective?
Select an answer first - 18
A forensic analyst is reviewing a Windows server's event logs. The baseline shows that the server typically has 10–15 interactive logons per day, all from the IT admin team. The analyst finds 50 interactive logons in one day, all from the same user account, with many occurring at odd hours. What is the most likely explanation?
Select an answer first - 19
What does a baseline of normal user activity typically include?
Select an answer first - 20
An analyst is establishing a baseline for a database server that runs critical applications. The server experiences peak usage during business hours and low usage at night. Which approach would best capture the normal performance baseline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.