GCFA › Analyzing Volatile and Windows Event Artifacts
This GCFA domain covers live-response and post-mortem analysis of memory and Windows event logs. Candidates must interpret process metadata, detect injection and hollowing, map network connections to PIDs, and read Security logon events. Questions use exhibits, multi-select, and scenario stems requiring tool-output interpretation rather than recall alone.
GCFA Analyzing Volatile and Windows Event Artifacts — All 52 Questions
Every question in this domain with answers and detailed explanations.