Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?

⚠ Common exam trap

The trap here is assuming that any process with logon ID 0x3e7 is automatically benign because it is SYSTEM, when in fact attackers frequently operate under SYSTEM and such events require deeper scrutiny.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The processes were created by the SYSTEM account, which often indicates that a service or scheduled task spawned them; this could be normal or malicious depending on the process.

The logon ID 0x3e7 is a well-known identifier for the SYSTEM account in Windows. Process creation events with this logon ID indicate that the process was spawned under the SYSTEM context, which is common for services and scheduled tasks. However, because attackers often escalate to SYSTEM, the analyst must examine the process name, command line, and parent process to determine if the activity is malicious. The logon ID alone is not sufficient to declare benign or malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The processes were created by the SYSTEM account, which often indicates that a service or scheduled task spawned them; this could be normal or malicious depending on the process.

    Why this is correct

    Logon ID 0x3e7 is the well-known logon ID for the SYSTEM account (NT AUTHORITY\SYSTEM). Processes with this logon ID are typically spawned by services, scheduled tasks, or other SYSTEM-level components. While this is normal for many system processes, attackers who gain SYSTEM privileges will also generate events with this logon ID. Therefore, the analyst must correlate the process name and command line to determine if it is suspicious.

  • ✗

    The processes were created by a user who logged on interactively, as indicated by the logon ID starting with 0x3, which denotes interactive logons.

    Why it's wrong here

    The logon ID is not structured with a prefix that denotes logon type. Logon IDs are hexadecimal values assigned by the LSA, and 0x3e7 is specifically the SYSTEM logon session. Interactive logons typically have different logon IDs (e.g., 0x3e5 for the first interactive logon). The '0x3' prefix is coincidental and not a reliable indicator of logon type.

  • ✗

    The processes were created by a user with a randomly assigned logon ID, which suggests the system is using logon session isolation for security.

    Why it's wrong here

    Logon IDs are not randomly assigned; they are generated by the Local Security Authority (LSA) and are unique per logon session. The value 0x3e7 is a fixed, well-known logon ID for the SYSTEM account. It is not a random value, and its presence does not indicate logon session isolation. Misinterpreting this as random could lead an analyst to overlook SYSTEM-level activity.

  • ✗

    The processes were created by a user with a well-known logon ID, which is typical for system services and indicates no malicious activity.

    Why it's wrong here

    The logon ID 0x3e7 is not a well-known logon ID for user accounts; it is specifically associated with the SYSTEM account. While processes created by SYSTEM are common, the presence of this logon ID in process creation events does not automatically rule out malicious activity, as attackers can use SYSTEM-level access. However, the key point is that 0x3e7 indicates SYSTEM, not a regular user.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.