Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?

⚠ Common exam trap

The trap here is relying on file size or hash lookups first, when the most obvious indicator is the unexpected directory combined with an invalid or missing Microsoft signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The file's digital signature and its original location in C:\Windows\System32

Legitimate Windows system executables like lsass.exe are stored in C:\Windows\System32 and are digitally signed by Microsoft. A copy found in C:\Windows\Temp is almost certainly malicious or a decoy. Verifying the digital signature and original location is a quick, offline method to confirm the file is not the genuine system process. Other checks like hash lookups or ACL review are useful but less immediate and definitive for this specific masquerading scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The file's digital signature and its original location in C:\Windows\System32

    Why this is correct

    The legitimate lsass.exe resides in C:\Windows\System32 and is digitally signed by Microsoft. A copy in C:\Windows\Temp is highly suspicious because system processes do not normally run from temporary directories. Verifying the digital signature and original location quickly confirms whether the file is the genuine Windows component or a masquerading malicious binary, making this the most direct first check.

  • ✗

    The file's hash against a threat intelligence database like VirusTotal

    Why it's wrong here

    Submitting the hash to a threat intelligence service is useful, but it requires internet access and may not have a record if the file is a custom or newly compiled tool. It is not the first characteristic to verify locally because it depends on external data and may not provide an immediate answer. The digital signature and location can be checked offline and are more definitive for masquerading system files.

  • ✗

    The file's access control list (ACL) to see if permissions were modified

    Why it's wrong here

    Modifying the ACL of a copied lsass.exe is not a typical attacker technique for masquerading; the primary indicator is the unusual location and invalid signature. Checking ACLs might reveal tampering but does not directly confirm whether the file is the legitimate Windows binary. It is a secondary check after establishing that the location and signature are anomalous.

  • ✗

    The file's size and version information compared to the known-good lsass.exe

    Why it's wrong here

    While size and version can differ, attackers often pad or modify binaries to match expected metadata, and version information can be forged. Checking size and version alone may not reveal tampering if the attacker copied the legitimate file and then modified it slightly. More reliable is verifying the digital signature and location, which are harder to fake without invalidating the signature.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.