
GIAC Certified Forensic Examiner
Domain 4Objective 2
Event Log Analysis GCFE Practice Questions (Page 6)
Part of the System and Device Analysis domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
5concepts
Questions 26–30
- 26
An analyst is investigating a Windows 10 system and needs to review events related to user logon and logoff. Which event log should the analyst examine?
Select an answer first - 27
An examiner is reviewing the Security log of a Windows 10 system and finds Event ID 4688 (process creation) with the following details: Parent Process: C:\Windows\System32\cmd.exe, New Process: C:\Users\Public\payload.exe. The examiner also finds Event ID 4104 in the PowerShell Operational log at the same time. What is the most likely sequence of events?
Select an answer first - 28
Which Windows event log is the primary repository for events generated by the operating system and its services, such as driver failures and service start/stop messages?
Select an answer first - 29
An analyst is investigating a Windows Server 2016 system and needs to review events related to system shutdowns and unexpected restarts. Which event log should the analyst examine?
Select an answer first - 30
An analyst is investigating a Windows 10 system and needs to find all events from the last 24 hours that have a Warning level in the System log. The analyst wants to use a built-in tool. Which command should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCFE” is a trademark of its owner, used for identification only.