Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Forensic Examiner

Domain 4Objective 2

Event Log Analysis GCFE Practice Questions (Page 3)

Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
5concepts

Questions 11–15

  1. 11application · medium

    An examiner finds Event ID 4732 in the Security log of a Windows Server. The event message states: 'A member was added to a security-enabled local group.' The subject is 'CONTOSO\jsmith' and the target group is 'Administrators'. What action did the user perform?

    Select an answer first
  2. 12application · medium

    An analyst is reviewing the Security log on a Windows 10 system and finds Event ID 4720, which indicates a user account was created. The analyst wants to determine which user account was created. Which field in the event entry should the analyst examine?

    Select an answer first
  3. 13expert · hard

    An analyst is investigating a possible privilege escalation. The analyst finds Event ID 4672 (special privileges assigned to new logon) in the Security log at 10:00, and Event ID 4688 (process creation) at 10:01. The analyst wants to confirm that the process was started with the elevated privileges. Which field in the 4688 event should the analyst examine?

    Select an answer first
  4. 14expert · hard

    An examiner is investigating a Windows 10 system and needs to determine whether a user ran a specific PowerShell command. The examiner has access to the PowerShell Operational log, but it appears to be empty. Which other log or source could contain evidence of PowerShell command execution?

    Select an answer first
  5. 15application · medium

    An analyst needs to export the last 100 Security log events from a Windows 10 system to a CSV file for further analysis in a spreadsheet. The analyst wants to use a built-in command-line tool. Which command should the analyst use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.