GIAC · Free Practice Questions · Last reviewed May 2026
48real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?
The file system metadata was actively corrupted by malware to hinder timeline analysis.
The file was copied from another location, preserving the original modified timestamp while generating a new creation timestamp.
Copying a file to a new NTFS destination assigns a fresh creation timestamp representing the exact moment of creation on the target volume. However, the modified timestamp is often preserved from the source file, creating an apparent chronological inversion that immediately flags the file as a copy.
The operating system experienced a severe clock synchronization failure during the write operation.
An automated defragmentation utility reorganized the cluster chain and inadvertently swapped the metadata values.
An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?
The ext4 journal aggressively overwrites inode metadata before user-space tools can parse the raw blocks.
The operating system automatically randomizes inode timestamps every 24 hours to prevent precise profiling.
Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.
Performance tuning options like relatime update access times only if the previous access time is older than the modification time or if it has been over a day. This intentional kernel behavior hides casual file reads, undermining traditional timeline analysis techniques used in incident response.
The Sleuth Kit parser inherently misinterprets the 64-bit epoch time structures utilized by modern Linux kernels.
When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?
Filtering increases the precision of the file system's internal clock
Filtering removes redundant entries to prevent system crashes during analysis
Filtering isolates relevant events from the massive volume of benign system activity
Super-timelines aggregate thousands of events, most of which are benign OS background tasks. Effective filtering narrows the scope to relevant timeframes or specific file types, enabling the analyst to quickly identify meaningful patterns of attacker behavior that would otherwise be obscured by the sheer volume of normal operating activity.
Filtering is required to encrypt the timeline output for secure storage
An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?
The file system is corrupted
The file was copied from an external source
When copying a file, the OS creates a new entry on the destination volume, setting a new birth time. However, many copy utilities and APIs preserve the original modification timestamp from the source file. This results in the metadata anomaly where the file appears to be 'modified' before it was 'born'.
The system clock was updated via NTP
The file is a system-level shadow copy
In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?
The difference between local time and UTC
The intentional modification of a file's timestamp
The discrepancy between the system clock and the actual time
Time skew represents the drift or offset of a system clock compared to an accurate reference time. It is a critical factor for forensic analysts to document; failing to account for it will result in an incorrect sequence of events when comparing the evidence against other system logs or external timestamps.
The process of normalizing timestamps to a common format
What is the primary function of the $LogFile in NTFS when reconstructing a timeline?
To store the actual file content data for quick retrieval
To track all user-level file access and modification events
To record metadata transactions for file system integrity
The $LogFile is an essential component for NTFS transaction integrity. For a forensic investigator, it provides a chronologically ordered record of metadata changes. This allows for the reconstruction of recent events, enabling the identification of file system activity even if the standard MFT record has been updated or overwritten.
To store backup copies of the Master File Table
Want more Introduction to File System Timeline Forensics practice?
Practice this domainAn analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?
The $LogFile
The $Bitmap
The MFT record
Resident files store their data directly within the MFT record structure when the file size is smaller than the remaining space in the record. This avoids allocating a cluster, effectively keeping the file content embedded within the MFT itself, which forensic analysts must extract directly from the MFT entry.
The $Extend folder
Which NTFS metadata file serves as the index for all files and directories on the volume?
$MFT
The $MFT file is the primary repository for all file metadata. It stores the file name, size, permissions, and data location for every object on the volume. Without the $MFT, the operating system would be unable to locate or manage files, and forensic analysis would be severely hindered.
$LogFile
$Boot
$Volume
What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?
To index directory contents.
To store extended file permissions.
To reference attributes stored in other MFT records.
When a file's attributes exceed the size of one MFT record, the $ATTRIBUTE_LIST attribute is created. It acts as a pointer map, listing the location and type of attributes held in additional MFT records, ensuring that the operating system can still access the complete metadata set for the file.
To track file deletion history.
What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?
It stores full file content for every transaction.
It has a much longer retention period.
The $UsnJrnl is designed to track volume changes for administrative purposes, leading to a much larger storage capacity compared to the circular, high-frequency $LogFile. This allows analysts to view long-term trends and historical file operations, which is crucial for reconstructive analysis during an incident response engagement.
It is not volatile and survives power loss.
It contains the actual NTFS security descriptors.
What is the primary role of the $MFTMirr file in NTFS?
To mirror all file contents.
To index all files in the system.
To provide a backup of the first MFT records.
The $MFTMirr file acts as a protective mechanism, storing a copy of the first few entries in the MFT. This allows the system to recover essential boot and file system metadata if the beginning of the MFT is corrupted, ensuring the volume remains accessible for basic operations.
To store encrypted file keys.
What does a non-resident $DATA attribute indicate in an NTFS MFT record?
The file is too small to be resident.
The file data is stored in separate clusters.
A non-resident attribute means the data is located outside the MFT record in physical data clusters. The attribute header contains 'data runs' that describe the starting cluster and the number of clusters occupied, which are essential for manual file carving and data reconstruction.
The file is corrupted.
The file is permanently deleted.
Want more NTFS Artifact Analysis practice?
Practice this domainRefer to the exhibit. What can be inferred about the file activity?
The file was created and immediately deleted.
The file was created and then populated with data.
The 'File_Create' event followed by the 'Data_Extend' event demonstrates that the file was initialized on the file system and then subsequently received data. This sequential logging is characteristic of standard file write operations performed by applications or the operating system, providing a clear timeline of file usage.
The file system is experiencing metadata corruption.
The timestamps reflect a timestomping attempt.
Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?
Updating system drivers
Timestomping
Timestomping is the intentional modification of file metadata to mislead investigators. By altering the SI attributes, an attacker hides the true age of a malicious file, making it appear as a legitimate system file or part of a different time window, which is a direct attack on forensic timeline integrity.
Log clearing
Clearing event logs is a classic anti-forensic measure taken to destroy the audit trail. Without log data, an investigator loses the capability to correlate file system events with user activity, preventing the reconstruction of an accurate narrative regarding how, when, and by whom a file was created or modified.
Using a web browser
Renaming a file
An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?
The MFT entry is locked by the OS kernel.
NTFS does not zero out MFT records upon deletion.
NTFS optimizes performance by simply marking MFT entries as available during deletion rather than zeroing out the data. This leaves the previous contents, including the FN attribute, intact in the record until a subsequent file creation operation overwrites it with new metadata, which is a core concept in forensic recovery.
The file was stored on a compressed volume.
The entry is hard-linked to another file.
Which of the following is true regarding the 'MFT Change' timestamp?
It is updated whenever the file's content changes.
It tracks when the file metadata was last modified.
The MFT Change timestamp reflects the last time the file's MFT record metadata was modified. This includes operations like renaming, changing permissions, or moving the file. It is a distinct temporal artifact from the file content modification time and provides critical context for structural changes to the file system.
It is easily modified by standard user applications.
It is identical to the file's creation time.
What is the primary function of the $LogFile in an NTFS file system?
To store user authentication logs.
To support file system recovery and consistency.
The $LogFile is a journal of transactions used by NTFS to ensure that the file system remains in a consistent state if a crash occurs. It tracks changes to metadata before they are finalized in the MFT, making it a critical source for investigating recent, volatile file system activity.
To track file access by unauthorized users.
To store the contents of deleted files.
An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?
The file was compressed using NTFS compression, which automatically updates the $STANDARD_INFORMATION modification timestamp while leaving $FILE_NAME untouched.
An automated defragmentation utility ran on the volume, updating the high-level metadata without altering the underlying filename structure.
The file was likely subjected to time-stomping where user-space tools altered the $STANDARD_INFORMATION attributes, leaving the original $FILE_NAME timestamps intact.
User-space anti-forensic tools typically modify only the easily accessible $STANDARD_INFORMATION attribute. Because the NTFS kernel driver maintains the $FILE_NAME attribute during standard renaming and creation actions, the older $FILE_NAME timestamp frequently survives, exposing the tampering attempt to investigators.
The operating system experienced an unclean shutdown, causing the lazy writer thread to flush $STANDARD_INFORMATION changes out of synchronization with $FILE_NAME.
Want more File System Timeline Artifact Analysis practice?
Practice this domainAn analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?
An interactive user logged into the local console, triggering default privilege escalation assignments.
A scheduled batch job executed locally using stored credentials without generating network authentication traffic.
An adversary performed lateral movement using stolen administrative credentials over the network to access administrative shares.
Logon Type 3 signifies a network authentication session, and Event ID 4672 explicitly records the assignment of special privileges to new logon sessions. Attackers routinely leverage network shares and administrative credentials to pivot across internal enterprise endpoints seamlessly.
A service account automatically restarted following a system crash, initiating local service control manager requests.
An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?
Perform a full disk imaging of the host immediately.
Execute an immediate reboot of the affected system.
Correlate the DNS query timestamps with socket ownership via netstat or EDR telemetry.
Mapping process IDs to remote network connections provides definitive proof of which executable is responsible for the beaconing. By comparing the process creation time and the socket initiation time, the analyst can identify the specific binary responsible for the traffic, which is a foundational step in host-based incident response.
Flush the local DNS resolver cache on the host.
Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?
The process is running as NT AUTHORITY\SYSTEM.
The parent process is services.exe.
The process is establishing an outbound connection to an external IP address.
Domain controllers should have strictly controlled outbound traffic profiles. An established connection to an arbitrary external IP address from a core infrastructure process like svchost is a classic indicator of compromise, suggesting the system is acting as a pivot or is participating in a command-and-control communication channel.
The process is using a high-numbered ephemeral port.
Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?
Event ID 4624 with Logon Type 10.
Logon Type 10 is the specific identifier for Remote Interactive logins, typically associated with RDP connections. This is the primary forensic artifact used to distinguish human-driven remote access from automated system tasks or background service authentication, which use different logon types within the Windows event auditing subsystem.
Event ID 4672 during the authentication process.
Event ID 4648 involving the use of explicit credentials.
Event ID 4720 occurring at the same time.
An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?
Run the script directly in a production environment to see its effect.
Use a base64 decoder to convert the command string to plaintext.
Decoding the base64 string reveals the original PowerShell code, which is essential for understanding the intended actions. This allows the analyst to identify malicious logic, such as network connections or file system changes, that the attacker was attempting to hide from traditional security monitoring tools and administrative logs.
Search for the command in the Windows Update history.
Check the local BIOS/UEFI logs for the command execution.
Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?
Utilizing WMI (Windows Management Instrumentation) to execute remote commands.
WMI is a powerful administrative framework that is frequently abused for remote code execution and lateral movement. Because WMI operations are essential for system management, they often blend in with normal administrative traffic, allowing attackers to maintain persistence and control without installing custom, easily detectable malware binaries.
Installing a custom kernel-mode rootkit for persistence.
Using Bitsadmin to download external payloads.
Bitsadmin is a native Windows tool for managing Background Intelligent Transfer Service jobs. Attackers use it to download payloads stealthily because it is a trusted system utility. Using legitimate administrative tools for unauthorized file transfers is a hallmark of LotL activity that evades simple binary-based blocking mechanisms.
Executing scripts via PowerShell to gather system information.
PowerShell is a standard administrative environment in Windows. Attackers leverage it to perform discovery, enumeration, and data collection. Since PowerShell is used daily by IT staff, malicious use is often overlooked by standard security monitoring, provided the attacker avoids triggering specific suspicious script block signatures or behavioral alerts.
Running a custom C++ backdoor compiled on the target.
Want more Identification of Malicious and Normal Activity practice?
Practice this domainAn incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?
The memory acquisition tool utilized an unprivileged user-mode API that restricted kernel visibility.
The malware executed direct kernel object manipulation to remove the process entries from the active process doubly-linked list.
DKOM lets malware unlink an EPROCESS entry from the active process doubly-linked list, so Volatility 3's list-walk traversal cannot reach it. The processes remain resident in memory, which is why the stem's aggressive kernel driver acquisition still captured them but standard enumeration missed them.
The operating system automatically paged the missing process control blocks out to the swap file during memory dumping.
Volatility 3 requires an outdated symbol table to correctly resolve the exact offsets of the Windows 10 kernel structures.
An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?
The Master File Table (MFT) entry
The Thread Environment Block (TEB)
The process structures in memory
Process hollowing involves creating a legitimate process in a suspended state and replacing its memory contents. The operating system maintains the PEB for legacy application compatibility, but the VAD tree manages the actual memory ranges mapped to the process. Mismatches here are a hallmark of process injection.
The System Service Descriptor Table (SSDT)
Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?
The PID 1240 is assigned to svchost.exe
The existence of two svchost.exe processes
The parent-child relationship of svchost.exe and explorer.exe
Explorer.exe is typically launched by userinit.exe during the login sequence. When svchost.exe, a process intended for background system services, spawns the shell, it indicates that the system has been compromised. This violation of established process lineage is a primary indicator of process injection or hollowing.
The PID of explorer.exe is higher than svchost.exe
An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?
The bit-depth of the monitor attached to the server
The footprint of the acquisition tool in RAM
Any tool executed on a system modifies memory. Minimizing the size and scope of the memory acquisition tool is vital to ensure that the evidence is not corrupted or overwritten. Forensic analysts prioritize tools that have a small footprint to maintain the integrity of the captured image.
The likelihood of a kernel panic during acquisition
Memory acquisition requires privileged access and interaction with kernel structures. If an acquisition tool is incompatible with the OS version or security software, it can trigger a kernel panic. Avoiding system crashes is critical for incident response, as a crash clears volatile memory and destroys evidence.
The total capacity of the hard drive
The current time zone of the server
Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?
The Master File Table (MFT)
The Process Environment Block (PEB)
The PEB is a user-mode data structure that contains essential information about a process, including the full command line used to launch it. Accessing this via memory forensics allows analysts to recover the exact execution path and any arguments passed to the malicious process, which are often missing.
The Registry Hive files
The System Service Descriptor Table (SSDT)
When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?
To ensure the memory image is encrypted correctly
To determine the correct offsets for kernel data structures
Kernel structures are highly dependent on the specific OS version and kernel build. The profile tells the forensic tool the exact location and size of these structures, such as process lists and thread blocks, ensuring that the tool parses the memory image accurately without data misalignment errors.
To increase the speed of the memory dumping process
To bypass the system's kernel-mode security drivers
Want more Introduction to Memory Forensics practice?
Practice this domainWhich conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?
The user performed an interactive console logon
The authentication utilized NTLMv1 or failed to negotiate encryption
A key length of 0 in an NTLM authentication event is a strong indicator of NTLMv1 usage or a failure to negotiate session security. This is critical for forensic analysts because NTLMv1 is cryptographically weak, and its presence often signals that an attacker is attempting to downgrade the authentication protocol.
The event represents a Kerberos ticket granting service request
The account was locked out due to excessive attempts
When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?
Event ID 4100
Event ID 4103
Event ID 4104
Event ID 4104 logs the script block content executed by the PowerShell engine. This is the primary event for forensic analysis of PowerShell activity, as it captures the full script, including base64-encoded commands, allowing analysts to decode and analyze the malicious logic used in fileless attacks.
Event ID 400
Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?
Memory Page Permissions (RWX)
Executable memory regions that are marked as Read-Write-Execute (RWX) are highly suspicious. Legitimate processes rarely require memory to be writable and executable simultaneously. Attackers often use these permissions to write shellcode to a buffer and then execute it, making this a primary indicator of process injection.
The system's Event Log files
Unbacked executable memory
Memory regions that contain executable code but are not mapped to a file on disk are indicative of shellcode. In a normal process, executable code is mapped from loaded DLLs or the main binary. Code existing in private memory without a backing file is a hallmark of reflective loading.
The MFT file records
Discrepancies in the Process VAD tree
The Virtual Address Descriptor (VAD) tree tracks the memory regions allocated to a process. By analyzing the VAD tree, an investigator can identify anomalies such as memory regions that have been allocated for code storage but lack a corresponding file mapping, which is a definitive sign of process hollowing or injection.
Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?
The command line contains -k netsvcs
The process path is C:\Windows\System32\
The ParentPID value
Svchost.exe is a critical system process that should always be spawned by services.exe. If the PPID does not match the process ID of services.exe, it strongly suggests that the process is a masquerading binary or has been launched by an unauthorized actor, even if the path appears correct.
The process name is svchost.exe
When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?
DNS cache
TCP Endpoint structures
TCP Endpoint structures in memory store the state of all active and listening network connections, including the associated process ID. By parsing these structures from a memory dump, an analyst can definitively link network traffic to a specific, potentially malicious process, regardless of whether the connection is hidden from standard OS tools.
Shimcache
Amcache.hve
An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?
Security.evtx
System.evtx
WMI-Activity/Operational.evtx
This log file specifically captures WMI events, including requests, queries, and process creation triggered by the WMI service. It is the most direct artifact for identifying malicious WMI activity, providing the necessary evidence to confirm that an attacker utilized this specific management interface for remote code execution.
Application.evtx
Want more Analyzing Volatile and Windows Event Artifacts practice?
Practice this domainDuring a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?
It removes sensitive PII from logs to ensure regulatory compliance.
It compresses log files, reducing storage costs for long-term retention.
It enables cross-platform correlation by providing a consistent event schema.
Normalization maps diverse log formats into a common format, allowing analysts to perform queries that span across different security devices. This consistency is critical for identifying lateral movement or multi-stage attacks where an actor touches multiple systems, ensuring that disparate events can be linked accurately during an incident investigation.
It automatically blocks malicious traffic detected within the log streams.
Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?
Identification
Containment
Recovery
Recovery is the phase where systems are restored, patches are applied, and security controls are validated to ensure the environment is safe for business operations. This step ensures that the root cause is addressed and that no residual access or persistence mechanisms remain that could allow the adversary to regain control.
Lessons Learned
An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?
Enable Credential Guard on all workstations and servers.
Credential Guard uses virtualization-based security to isolate secrets in a protected container. By preventing access to the LSA process memory, it stops attackers from extracting NTLM hashes or Kerberos tickets, which are the fundamental building blocks for Pass-the-Hash and Pass-the-Ticket attacks, significantly hardening the host against lateral movement.
Disable NTLM authentication and force Kerberos usage.
NTLM is inherently vulnerable to relay and capture-based attacks because it relies on challenge-response mechanisms that do not provide mutual authentication. Disabling NTLM forces the use of Kerberos, which is much more secure, does not expose static password hashes in the same way, and prevents the simple PtH attack vector.
Implement Local Administrator Password Solution (LAPS).
LAPS ensures that the local administrator password on every machine in the domain is unique and randomly generated. This prevents an attacker who gains access to one machine from using the same local admin credentials to compromise every other machine in the enterprise, effectively stopping simple password-based lateral movement.
Increase the minimum password length requirement to 20 characters.
Regularly scan for and remove all local user accounts.
An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?
To bypass the need for multi-factor authentication on local machines.
To gain unrestricted control over the entire domain and its resources.
Domain Admin is the most powerful privilege level in a Windows domain. By successfully compromising this group, an attacker inherits the ability to perform any action on any object within the domain, effectively giving them complete authority to manipulate resources, settings, and user access across the whole enterprise network.
To encrypt the Active Directory database for ransomware demands.
To hide their tracks by clearing the Windows Event logs globally.
Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?
Using a Domain Admin account for all investigation tasks to avoid access issues.
Granting forensic responders full system access to all network segments.
Limiting IR account access to only the specific data and systems needed for the investigation.
By limiting the permissions of an IR account to exactly what is needed—such as log reading or forensic disk access—the organization mitigates the risk of credential theft. This practice ensures that even if an account is compromised, the attacker is limited in their ability to escalate or expand their foothold.
Ensuring all IR accounts have a shared password for rapid response coordination.
An organization discovers that an attacker is using 'Living off the Land' (LotL) binaries to execute malicious code. Why are LotL attacks particularly difficult to detect in an enterprise environment?
The tools are specifically designed by attackers to bypass security.
They operate entirely in memory and leave no file system artifacts.
They utilize trusted system processes that are frequently used by administrators.
LotL attacks abuse legitimate tools such as PowerShell or WMI that are already trusted by the OS and security software. Since administrators use these same tools for daily tasks, it is difficult to identify which executions are malicious without advanced behavioral analysis that correlates multiple logs and process metadata.
The attacker encrypts the binaries so antivirus cannot scan them.
Want more Enterprise Environment Incident Response practice?
Practice this domainWhen analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?
Run dialog commands
Windows Explorer navigation paths
TypedPaths records the history of directory paths the user manually typed into the File Explorer address bar. This provides a direct record of the user's navigational intent, which is particularly useful for identifying access to sensitive directories that are not typically visible through standard menu-based browsing.
Recently opened documents
External device connection history
An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?
File Creation Timestamp
File Attribute Flags (MFT)
The MFT stores the attributes for every file on an NTFS volume. The 'Hidden' attribute flag, when set, instructs the operating system to omit the file from standard folder views. Identifying this flag is essential for uncovering files that the attacker intentionally obscured from the user.
Extended Attributes (EA)
Access Control List (ACL)
Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?
Prefetch files
USBSTOR Registry Key
The USBSTOR key in the SYSTEM hive acts as a central repository for all USB device connections. It stores the vendor, product ID, and serial number of the device. Even after the device is disconnected, this entry remains, providing a permanent record of the hardware's interaction with the system.
ShellBags
SRUM (System Resource Usage Monitor)
Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?
SYSTEM hive; tracking system services
NTUSER.DAT hive; tracking user-initiated program execution
UserAssist is located in the NTUSER.DAT hive, which is unique to each user profile on the system. It tracks the programs the user launches via the Windows shell, recording execution counts and timestamps, making it the primary artifact for identifying user-driven activity during an investigation.
SOFTWARE hive; tracking installed application paths
SECURITY hive; tracking authentication logs
An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?
It records the exact UTC execution time for all files in the SYSTEM hive.
Entries are only populated when the UserAssist key is enabled in the registry.
It tracks file path and last modification time for potential application compatibility.
Shimcache stores the file path and the last modified time of the executable. This helps the OS determine if a file is compatible. For forensics, this artifact is essential for identifying executable files that existed on the system, even if those files were subsequently deleted by an attacker.
It is stored within the NTUSER.DAT hive for each individual user profile.
An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?
It records the deletion of a user account from the local database.
It logs that a system service was started by the Service Control Manager.
It signals the installation of a new service on the system.
Event 4697 tracks service installation. Attackers often install services to maintain persistence, ensuring their malware runs with high privileges after a reboot. Detecting this event allows the investigator to extract the service path and identify the malicious binary that was dropped and registered for automatic execution.
It documents a failed attempt to modify an existing service.
Want more Windows Artifact Analysis practice?
Practice this domainThe GCFA exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 8 domains: Introduction to File System Timeline Forensics, NTFS Artifact Analysis, File System Timeline Artifact Analysis, Identification of Malicious and Normal Activity, Introduction to Memory Forensics, Analyzing Volatile and Windows Event Artifacts, Enterprise Environment Incident Response, Windows Artifact Analysis. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official GIAC GCFA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.