GCFA Practice Question: Identification of Malicious and Normal Activity
A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)
⚠ Common exam trap
The trap here is equating any recurring logon or service event with beaconing, when beaconing specifically requires repeated network or DNS activity tied to a process over time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sysmon Event ID 3 (NetworkConnect) entries showing repeated connections to the same external IP at regular intervals.
Beaconing is characterized by repeated, regular communication from a host to an external controller. Sysmon network-connect events and DNS query events both capture the timing, destination, and initiating process needed to confirm that pattern directly from the endpoint. Logon, application-crash, and service-install events may support the broader investigation but do not, by themselves, demonstrate periodic outbound C2 traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application Event ID 1000 (Application Error) entries referencing a crashing service.
Why it's wrong here
Application Error events record user-mode crashes and faulting module paths. While a crashing service could occasionally be a symptom of a poorly written implant, crash events are not correlated with periodic outbound traffic and do not demonstrate beaconing. Many benign applications crash routinely, so this artifact offers little direct value for confirming command-and-control timing or destination.
- ✗
System Event ID 7045 (A service was installed in the system) recorded once during the investigation window.
Why it's wrong here
Event ID 7045 records service installation, which is a persistence mechanism rather than a beaconing indicator. A single service-install event does not show repeated outbound communication or timing patterns. Investigators should treat 7045 as a pivot to examine the installed binary and its network behavior, but on its own it does not directly evidence periodic C2 beaconing.
- ✓
Sysmon Event ID 3 (NetworkConnect) entries showing repeated connections to the same external IP at regular intervals.
Why this is correct
Sysmon Event ID 3 records outbound network connections with process, source, destination, and port details. Repeated connections to the same external IP at consistent intervals are a hallmark of beaconing and directly evidence command-and-control traffic. Correlating the initiating process image and its hash strengthens the finding, making this one of the most direct artifacts for confirming periodic C2 behavior from the endpoint itself.
- ✗
Security Event ID 4624 (An account was successfully logged on) with Logon Type 3 repeated every few minutes.
Why it's wrong here
Logon Type 3 denotes a network logon, commonly generated by SMB, IIS, or remote administration activity. Beaconing malware typically uses raw HTTP, HTTPS, or DNS rather than SMB, so it does not generate 4624 Type 3 events. Repeated network logons may indicate scanning or a service account, but they are not direct evidence of periodic C2 beaconing to an external controller.
- ✓
Sysmon Event ID 22 (DNSEvent) entries showing queries to the same domain at consistent time intervals.
Why this is correct
Sysmon Event ID 22 captures DNS queries with the querying process and the resolved results. A process issuing DNS lookups to the same domain on a regular cadence is a strong indicator of DNS-based beaconing, which is common in modern malware. Pairing the querying image path with the queried domain provides direct, endpoint-side evidence of periodic C2 resolution behavior.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.