GCFA Practice Question: Identification of Malicious and Normal Activity
A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?
⚠ Common exam trap
The trap here is relying on event ID 4697 for service installation evidence, but that event is only generated when a non-default audit policy is enabled, so it may be absent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SYSTEM registry hive, specifically the LastWrite time of the service key under HKLM\SYSTEM\CurrentControlSet\Services.
The LastWrite time of the service's registry key in the SYSTEM hive provides a direct timestamp for when the service configuration was last modified, which for a newly created service correlates with its installation. This artifact is stored locally and does not depend on audit policies. Other options either require non-default auditing, do not record service creation, or reflect file activity rather than service configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The NTFS $MFT, checking the timestamps of the updater.exe file in C:\Users\Public.
Why it's wrong here
The $MFT timestamps show when the executable file was created or modified, but they do not confirm when the service was created or configured. An attacker could create the executable earlier and later install it as a service. The service's registry key LastWrite time is more directly tied to the service creation. Additionally, timestomping could alter the file's timestamps, making them unreliable for this purpose.
- ✓
The SYSTEM registry hive, specifically the LastWrite time of the service key under HKLM\SYSTEM\CurrentControlSet\Services.
Why this is correct
The LastWrite time of a registry key indicates when the key was last modified. For a newly created service, the LastWrite time of its key in the SYSTEM hive will reflect the creation or last modification time. If this time correlates with the suspected infection window and the service binary is in a user-writable directory, it strongly suggests the service is malicious. Legitimate Windows services typically have older, consistent LastWrite times.
- ✗
The Amcache.hve file, checking for the service binary path under the Root\InventoryApplicationFile key.
Why it's wrong here
Amcache.hve tracks application execution and file metadata, not service creation. While it might contain an entry for updater.exe if it executed, it does not record when the service was created or its configuration. The service creation is best evidenced by the registry key's LastWrite time or service installation events, not by Amcache, which focuses on program installation and execution traces.
- ✗
The Security event log, looking for event ID 4697 (A service was installed in the system).
Why it's wrong here
Event ID 4697 does indicate a service installation, but it is only logged if the audit policy 'Audit Security System Extension' is enabled, which is not default. The scenario does not state that this policy was enabled, so the event may not exist. Even if present, it does not provide the registry key's LastWrite time, which is a more direct artifact for confirming the service's creation time from the registry hive itself.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.