Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?

⚠ Common exam trap

The trap here is assuming that enabling process creation auditing automatically includes command line data; in reality, a separate policy must be enabled to capture that detail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the 'Include command line in process creation events' policy under Administrative Templates > System > Audit Process Creation.

The 'Include command line in process creation events' policy is the specific setting that controls whether the command line is recorded in Event ID 4688. Enabling it ensures that future process creation events contain the full command line, which is essential for identifying malicious commands. Other audit policies enable the event but do not add command line data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Turn on PowerShell Script Block Logging' policy under Administrative Templates > Windows Components > Windows PowerShell.

    Why it's wrong here

    This policy logs PowerShell script block content to the PowerShell operational log, not to Security Event ID 4688. It would not affect the command line field in process creation events. It is useful for PowerShell activity but not for command line capture in 4688.

  • ✗

    Enable the 'Process Creation' audit policy under Local Policies > Audit Policy.

    Why it's wrong here

    The legacy Process Creation audit policy is the predecessor to Advanced Audit Policy and also does not include command line data. It enables logging of process creation but without command line details. Thus, it would not populate the command line field.

  • ✓

    Enable the 'Include command line in process creation events' policy under Administrative Templates > System > Audit Process Creation.

    Why this is correct

    This policy, when enabled, configures Windows to include the full command line in Event ID 4688 process creation events. Without it, the command line field is blank. Enabling it ensures future events capture this critical detail for forensic analysis.

  • ✗

    Enable the 'Audit Process Creation' policy under Advanced Audit Policy Configuration > Detailed Tracking.

    Why it's wrong here

    Enabling Audit Process Creation turns on the logging of Event ID 4688, but it does not populate the command line field. The command line inclusion is controlled by a separate policy. This setting alone would still result in empty command line fields.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.