Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.
Start practicing
Analyzing Volatile and Windows Event Artifacts — choose a session length
Free · No account required
Domain overview
This GCFA domain covers live-response and post-mortem analysis of memory and Windows event logs. Candidates must interpret process metadata, detect injection and hollowing, map network connections to PIDs, and read Security logon events. Questions use exhibits, multi-select, and scenario stems requiring tool-output interpretation rather than recall alone.
Exam objectives
Interpreting process metadata from memory tools like Volatility and Rekall for anomalies
Detecting process hollowing and code injection via memory artifacts and thread inspection
Correlating network connections to process IDs using netstat, Volatility netscan, and handles
Reading Windows Security event IDs for logon type, account, and interactive session timing
Confusing parent-child process relationships with injected code; a legitimate parent can spawn a hollowed child, so verify image path and memory mapping.
Treating every hidden or unlinked connection as malicious; terminated processes and kernel structures can leave stale entries that require corroboration.
Misreading logon event IDs: 4624 is a logon, 4625 failure, 4634 logoff, and logon type 2 versus 10 changes the interpretation entirely.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?
2When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?
3Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?
4Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?
5When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?
6An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?
7An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?
8Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?
9Which artifact is the primary location for finding 'Shellbag' data, which tracks user folder access history?
10An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?
11Which of the following best describes the function of the 'UserAssist' registry key in a Windows forensic investigation?
12Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?
13During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?
14During a live response on a Windows 10 workstation suspected of lateral movement, you capture volatile memory and also export the Windows Event Logs. You need to correlate a process that was running at the time of capture with its parent process and the user account that launched it, using only the memory image. Which Volatility 3 plugin should you run to produce a parent-child process tree with PID/PPID, image name, and offset columns?
15A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)
16A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?
17You are examining a Windows Server 2019 memory image after a suspected credential-theft incident. You need to identify which process was used to access the LSASS process memory at the time of capture. Which Volatility 3 plugin and artifact combination most directly reveals handles opened to the LSASS process by other processes?
18A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)
19A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?
20A Windows 10 endpoint was compromised, and the attacker cleared the Security event log after establishing persistence. You have a memory image captured after the clearing. Which Windows Event Log artifact can still provide evidence of the log-clearing action, even if the Security log entries were wiped?
21A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?
22An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?
23An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?
24An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?
25During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?
26During an investigation of a compromised Windows Server 2019, an analyst extracts the ShimCache (AppCompatCache) from the SYSTEM registry hive. The analyst needs to determine which executable was present on the system but may have been deleted. Which artifact within the ShimCache entry provides the best indication of file existence and last modification time?
27You are reviewing a Windows 10 host for evidence of process execution. A suspect binary was deleted from disk, but you need to prove it actually ran. Which artifact provides the strongest evidence that the specific executable was launched, independent of any prefetch or shimcache entries?
28During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?
29An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?
30An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Which event ID should the analyst examine to find this information?
31A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?
32An analyst is examining a Windows 10 system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log should be examined to find the most recent interactive logon event?
33During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)
34An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)
35An analyst is reviewing a Windows 10 system and wants to determine the last time the system was shut down. Which Windows event log and event ID should the analyst examine?
36An analyst is examining a Windows system and needs to determine when a USB mass storage device was last connected. Which registry artifact should be examined to find the device's first and last connection times?
Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.
The Courseiva GCFA question bank contains 36 questions in the Analyzing Volatile and Windows Event Artifacts domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Analyzing Volatile and Windows Event Artifacts domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included