GCFA › Identification of Malicious and Normal Activity
This domain tests your ability to distinguish malicious from benign activity using Windows artifacts: Security event logs, Sysmon, memory, and file system metadata. Questions present scenarios like credential dumping, logon anomalies, or botnet triage and ask which artifacts or event IDs confirm the activity. You must know event IDs, logon types, and tool outputs.
GCFA Identification of Malicious and Normal Activity — All 62 Questions
Every question in this domain with answers and detailed explanations.