GCFA Practice Question: Identification of Malicious and Normal Activity
A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)
⚠ Common exam trap
The trap here is selecting artifacts that show any malicious activity, such as prefetch or ShimCache, without considering that fileless attacks specifically avoid leaving such disk-based traces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PowerShell operational log event ID 4104 containing an encoded script that decodes to a reflective loader
Fileless malware operates by injecting code into memory and often uses scripts like PowerShell to load payloads reflectively without writing executables to disk. Finding injected code in a legitimate process's memory via memory forensics, combined with a PowerShell script block log showing an encoded reflective loader, provides strong evidence of an active fileless attack. The other artifacts—prefetch, service creation with a binary, and ShimCache—all indicate disk-based execution, which is inconsistent with a fileless attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PowerShell operational log event ID 4104 containing an encoded script that decodes to a reflective loader
Why this is correct
Event ID 4104 captures script block content, and an encoded script that decodes to a reflective loader is a classic fileless technique. Reflective loaders execute code directly in memory without writing to disk. This artifact provides evidence of the initial execution vector and the malicious payload, and when combined with memory injection evidence, strongly confirms an active fileless attack.
- ✓
Injected code in the memory of a legitimate process, such as explorer.exe, visible through memory forensics
Why this is correct
Fileless malware often injects malicious code into the memory space of a legitimate process to evade disk-based detection. Finding injected code or unusual memory regions in a trusted process like explorer.exe is a strong indicator of fileless execution. Memory forensics can reveal these anomalies, such as RWX memory pages or unexpected threads, which are not present in a clean system.
- ✗
An entry in the ShimCache (AppCompatCache) for a malicious binary
Why it's wrong here
ShimCache records the execution of binaries from disk, similar to prefetch. Its presence indicates that a file was executed on the system, which is not typical of fileless malware. While ShimCache can be useful for tracking disk-based execution, it does not provide evidence of fileless techniques and would be more relevant to a traditional malware investigation.
- ✗
A newly created service with a binary path pointing to a suspicious executable in C:\Windows\Temp
Why it's wrong here
A new service with a binary path to an executable on disk indicates a disk-based persistence mechanism, not a fileless attack. Fileless malware typically avoids creating files and may use other persistence methods like WMI event subscriptions or registry modifications. The presence of a service binary would suggest the attacker dropped a file, which is contrary to the fileless scenario.
- ✗
A prefetch file for a known malicious executable on disk
Why it's wrong here
Prefetch files are created when an executable runs from disk. Fileless malware typically does not write an executable to disk, so a prefetch file for a malicious executable would indicate a disk-based attack, not a fileless one. Its presence would actually contradict the fileless hypothesis, making it a poor choice for evidence of fileless activity.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.