
GIAC Certified Forensic Analyst
Domain 5Objective 1
Identification of Normal System and User Activity GCFA Practice Questions (Page 7)
Part of the Activity Analysis domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
3concepts
Questions 31–35
- 31
A security team is establishing a baseline for a new server that will host a public-facing web application. The team has no historical data for this server. Which approach is most effective for establishing a baseline that will be useful for anomaly detection?
Select an answer first - 32
An analyst is establishing a baseline for a database server that supports a customer-facing application. The server experiences high CPU usage during business hours and low usage at night. The analyst needs to identify anomalies without generating excessive false positives. Which approach is most effective?
Select an answer first - 33
An analyst is reviewing authentication logs for a company that uses multi-factor authentication (MFA). The baseline shows that users typically authenticate from the office network during business hours. The analyst notices that a user authenticated successfully from a coffee shop IP address at 3 PM, and the MFA prompt was approved. What is the most likely explanation?
Select an answer first - 34
A forensic analyst is establishing a baseline for a database server that runs critical applications. The baseline should include process lists, network connections, and performance metrics. Which additional data source would be most valuable for detecting anomalies related to unauthorized access?
Select an answer first - 35
A forensic analyst is reviewing a user's activity on a corporate workstation. The baseline shows that the user typically works from 9 AM to 5 PM, accesses the accounting software, and uses email. The analyst notices that the user logged in at 2 AM and ran a PowerShell script that compressed and encrypted several files. What is the most likely explanation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFA” is a trademark of its owner, used for identification only.