GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?
⚠ Common exam trap
Many candidates confuse PowerShell's persistent PSReadLine history file with cmd.exe console history, which is only held in conhost.exe memory and not saved to disk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The console history buffer in the conhost.exe process memory.
The console history buffer in conhost.exe memory contains the commands typed in a command prompt window during the session. This volatile artifact is not written to disk by default, so it can only be recovered from a memory image. The PSReadLine history file is for PowerShell and is persistent, while event logs and cmdline plugins do not capture interactive command history. Therefore, the conhost.exe buffer is the correct source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The windows.cmdline plugin output showing the command line of cmd.exe.
Why it's wrong here
windows.cmdline displays the command line arguments used to launch a process. For cmd.exe, this would only show how the command prompt was started (e.g., just 'cmd.exe' or with /k), not the subsequent commands typed interactively. It does not capture the console history buffer, so it cannot reveal recently typed commands.
- ✗
The Windows Event Log 'Microsoft-Windows-CommandPrompt/Operational' with command history events.
Why it's wrong here
Windows does not have a built-in operational event log that records command prompt command history by default. While process creation events (4688) can log command lines if auditing is enabled, they do not provide a history of commands typed within an interactive console session. This log source does not exist for that purpose.
- ✓
The console history buffer in the conhost.exe process memory.
Why this is correct
The Windows Console Host (conhost.exe) maintains a history buffer of commands entered in a command prompt window. This buffer resides in the memory of the conhost.exe process associated with the console session. Extracting this buffer from a memory image can reveal recently typed commands that may not be recorded in any persistent log, making it a valuable volatile artifact for user activity.
- ✗
The PowerShell console history file at %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt.
Why it's wrong here
The PSReadLine history file stores PowerShell commands typed in the PowerShell console, not commands typed in a traditional cmd.exe command prompt. It is a persistent file on disk and would not be found in a memory image unless the file content was cached. It is specific to PowerShell and does not capture cmd.exe console history.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.