20+ practice questions focused on Windows Artifact Analysis — one of the most tested topics on the GIAC Certified Forensic Analyst exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Windows Artifact Analysis PracticeAn analyst discovers a suspicious executable in a user's AppData folder. Which Windows artifact should be examined first to determine if the file was executed via a specific user action or a scheduled task?
Explanation: UserAssist tracks GUI-based application execution, while Prefetch provides execution history regardless of the launch method. To differentiate between user-driven execution and background tasks, an analyst must correlate UserAssist entries with the Task Scheduler logs or Prefetch files. Understanding the launch vector is critical to determining if the activity was manual interaction or automated persistence, which guides the subsequent scope of the investigation into potential lateral movement or malicious automation.
Which TWO of the following artifacts are most effective for identifying file system activity that occurred immediately before a system shutdown or sudden crash?
Explanation: Analyzing recent file activity requires artifacts that persist across volatile states. The Registry's ShellBags preserve folder view settings, and the RecentDocs key tracks items accessed through the Windows shell. By examining these, analysts can reconstruct the final user actions before a loss of power or system crash. This is vital for incidents involving anti-forensics or attempts to hide evidence by inducing a system failure to prevent proper log flushing.
Refer to the exhibit. Based on the USN Journal output, what can the analyst conclude about the file 'secret_data.docx'?
Explanation: The USN Journal logs low-level modifications to the NTFS volume. The presence of 'FileCreate' followed by 'DataOverwrite' and 'Close' indicates the file was generated and then modified within the same timeframe. This allows an analyst to build a precise sequence of events for a specific file. Understanding these flags is critical for proving data staging or exfiltration activities when other high-level application logs may have been wiped by the adversary.
An analyst is investigating a compromised system and finds that the 'LastWrite' time of a specific registry key has been modified to match the surrounding keys. Which artifact should be checked to detect this timestomping attempt?
Explanation: Registry keys do not maintain a comprehensive history of modification times, making them vulnerable to timestomping. However, the Transaction Logs (hive transaction files) and the USN Journal record low-level file system and registry transactions. By comparing the high-level registry timestamps with the low-level journal entries, an analyst can detect discrepancies. This is essential for uncovering sophisticated attackers who attempt to blend in by falsifying temporal evidence during a post-exploitation phase.
Which THREE pieces of information can be extracted from a parsed Windows 'Jump List' artifact?
Explanation: Jump Lists are essential for understanding user interaction with specific applications. They record recently accessed files, pinned items, and the application ID associated with those objects. By analyzing these, an analyst can determine if a user opened sensitive documents or used specific tools, providing a window into their recent workflow. This artifact is a primary target for evidence of data exfiltration, as it captures the file paths and access times of opened documents.
+15 more Windows Artifact Analysis questions available
Practice all Windows Artifact Analysis questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Windows Artifact Analysis. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Windows Artifact Analysis questions on the GCFA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Windows Artifact Analysis is tested as part of the GIAC Certified Forensic Analyst blueprint. Practicing with targeted Windows Artifact Analysis questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCFA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Windows Artifact Analysis is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Windows Artifact Analysis practice session with instant scoring and detailed explanations.
Start Windows Artifact Analysis Practice →