Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?

⚠ Common exam trap

The trap here is assuming that command-line auditing or memory command-line plugins capture the full PowerShell script, when they only show how the process was started and not the script blocks executed at runtime.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows PowerShell event log, event ID 4104 (Script Block Logging).

Script Block Logging (event ID 4104) captures the actual PowerShell code that runs, including obfuscated or dynamically constructed script blocks, and writes it to the Windows PowerShell operational log. This is the most direct artifact for determining what a malicious PowerShell script did. Command-line auditing and memory plugins can show how PowerShell was launched but not the full script content. Therefore, the PowerShell event log with 4104 is the best source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The windows.cmdline plugin output from the memory image showing the PowerShell process command line.

    Why it's wrong here

    The windows.cmdline plugin retrieves the command line arguments for processes from memory. While this can show the PowerShell command line used to start the process, it does not provide the actual script block content that was executed. If the script was passed via -EncodedCommand or from a file, the command line alone will not reveal the full script logic.

  • ✗

    Windows Security event log, event ID 4688 (Process Creation) with command-line auditing enabled.

    Why it's wrong here

    Event ID 4688 with command-line auditing shows the command line used to launch a process, including the PowerShell invocation. However, it only captures the initial command line and does not show the full script block content, especially if the script was loaded from a file or encoded. It is useful for process lineage but not for extracting the complete executed script.

  • ✗

    The windows.pslist plugin output showing the PowerShell process and its parent process.

    Why it's wrong here

    windows.pslist enumerates active processes from the active process list, providing process names, PIDs, and parent PIDs. It can confirm that PowerShell was running and identify its parent, but it contains no information about the script block content or command-line arguments. It is useful for process discovery but not for script reconstruction.

  • ✓

    Windows PowerShell event log, event ID 4104 (Script Block Logging).

    Why this is correct

    Event ID 4104 in the Windows PowerShell operational log records the actual script block text when Script Block Logging is enabled. This directly captures the PowerShell code that was executed, including obfuscated or dynamically generated content, making it the most direct source for reconstructing the malicious script block. It is not enabled by default, so its presence indicates prior configuration.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.