GCFA Practice Question: Identification of Malicious and Normal Activity
A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?
⚠ Common exam trap
The trap here is relying on file size or hash lookups first, when the most obvious indicator is the unexpected directory combined with an invalid or missing Microsoft signature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The file's digital signature and its original location in C:\Windows\System32
Legitimate Windows system executables like lsass.exe are stored in C:\Windows\System32 and are digitally signed by Microsoft. A copy found in C:\Windows\Temp is almost certainly malicious or a decoy. Verifying the digital signature and original location is a quick, offline method to confirm the file is not the genuine system process. Other checks like hash lookups or ACL review are useful but less immediate and definitive for this specific masquerading scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The file's digital signature and its original location in C:\Windows\System32
Why this is correct
The legitimate lsass.exe resides in C:\Windows\System32 and is digitally signed by Microsoft. A copy in C:\Windows\Temp is highly suspicious because system processes do not normally run from temporary directories. Verifying the digital signature and original location quickly confirms whether the file is the genuine Windows component or a masquerading malicious binary, making this the most direct first check.
- ✗
The file's hash against a threat intelligence database like VirusTotal
Why it's wrong here
Submitting the hash to a threat intelligence service is useful, but it requires internet access and may not have a record if the file is a custom or newly compiled tool. It is not the first characteristic to verify locally because it depends on external data and may not provide an immediate answer. The digital signature and location can be checked offline and are more definitive for masquerading system files.
- ✗
The file's access control list (ACL) to see if permissions were modified
Why it's wrong here
Modifying the ACL of a copied lsass.exe is not a typical attacker technique for masquerading; the primary indicator is the unusual location and invalid signature. Checking ACLs might reveal tampering but does not directly confirm whether the file is the legitimate Windows binary. It is a secondary check after establishing that the location and signature are anomalous.
- ✗
The file's size and version information compared to the known-good lsass.exe
Why it's wrong here
While size and version can differ, attackers often pad or modify binaries to match expected metadata, and version information can be forged. Checking size and version alone may not reveal tampering if the attacker copied the legitimate file and then modified it slightly. More reliable is verifying the digital signature and location, which are harder to fake without invalidating the signature.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.