20+ practice questions focused on Identification of Malicious and Normal Activity — one of the most tested topics on the GIAC Certified Forensic Analyst exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Identification of Malicious and Normal Activity PracticeWhich TWO of the following indicators are highly suggestive of credential dumping activity in memory?
Explanation: Credential dumping tools often interact with the Local Security Authority Subsystem Service (LSASS) to extract hashes or plain-text passwords. Observing process access requests to LSASS by non-system processes is a primary indicator. Furthermore, the presence of specific temporary files or unusual command-line arguments used by known post-exploitation frameworks provides high-confidence signatures that security analysts can use to confirm an active credential theft attempt during an investigation.
Refer to the exhibit. What type of attack is demonstrated in this server response?
Explanation: The injected script attempts to capture the user's session cookie and exfiltrate it to an external domain. This is a hallmark of a Cross-Site Scripting (XSS) attack. By embedding malicious JavaScript into the HTML response, the attacker can execute code within the context of the user's browser, potentially stealing session identifiers or performing actions on behalf of the authenticated user to compromise their account access.
Which artifact is most useful for detecting unauthorized persistence via a Windows registry Run key?
Explanation: The registry contains several 'Run' and 'RunOnce' keys that launch applications upon user or system startup. Malicious actors frequently modify these keys to ensure their malware survives a reboot. Auditing registry changes (via System Monitor/Sysmon) or examining the registry hive files offline during forensics provides the visibility needed to identify hidden persistence mechanisms that are not easily visible through standard process list reviews.
During a forensic analysis, you find a 'shimcache' (AppCompatCache) entry for an executable that no longer exists on the disk. What does this confirm?
Explanation: The Shimcache is designed to track application compatibility and is populated upon execution. An entry in the Shimcache confirms that a specific binary was present and executed on the system at some point, even if the file has been subsequently deleted. This is a critical artifact for establishing a timeline of activity, specifically for identifying malware that an attacker attempted to remove to hide their forensic tracks.
A security analyst observes a workstation periodically initiating outbound HTTPS connections to an external IP address at exactly 03:00 UTC. The forensic artifact shows the process associated with these connections is 'svchost.exe' with a PID that changes daily. Which indicator strongly suggests malicious activity rather than a standard scheduled task?
Explanation: Standard Windows services initiated by svchost.exe typically reference a Service Host group and a specific DLL path found in the registry under HKLM\System\CurrentControlSet\Services. When the parent process structure is decoupled from the services.exe hierarchy, or when the binary location deviates from System32, it signals process injection or masquerading. Identifying these discrepancies is vital for isolating beaconing activity in sophisticated persistent threats that attempt to blend into normal system baseline traffic.
+15 more Identification of Malicious and Normal Activity questions available
Practice all Identification of Malicious and Normal Activity questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Identification of Malicious and Normal Activity. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Identification of Malicious and Normal Activity questions on the GCFA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Identification of Malicious and Normal Activity is tested as part of the GIAC Certified Forensic Analyst blueprint. Practicing with targeted Identification of Malicious and Normal Activity questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCFA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Identification of Malicious and Normal Activity is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Identification of Malicious and Normal Activity practice session with instant scoring and detailed explanations.
Start Identification of Malicious and Normal Activity Practice →