GCFA • Practice Test 7
Free GCFA practice test — 10 questions with explanations. Set 7. No signup required.
You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?
Choose an answer to begin — your selection is scored in the full session.
10 questions · instant feedback and full explanations after every question.