GCFA Enterprise Environment Incident Response Practice Question
A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?
⚠ Common exam trap
The trap here is focusing on endpoint logs that show execution, while overlooking the email gateway logs that directly record the phishing email and its attachment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email gateway logs
Email gateway logs are specifically designed to record email metadata and content, including attachments. In a phishing incident, these logs provide the earliest evidence of the attack, showing the malicious email's delivery, sender, and attachment details. This allows responders to identify the initial vector, block similar emails, and notify other potential victims. Other log sources may show subsequent activity but lack the email context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Security event logs on the domain controller
Why it's wrong here
Domain controller security logs primarily record authentication and authorization events, such as logons and group membership changes. They would not typically record the execution of a malicious attachment on a user's workstation. While they might show lateral movement using compromised credentials, they are not the best source for the initial phishing vector.
- ✗
Sysmon logs on user workstations
Why it's wrong here
Sysmon logs can provide detailed process creation, network connections, and file operations. They might show the execution of a malicious process from an email client's temporary folder, but they do not record the email itself or its attachment. While valuable for understanding post-infection activity, they are not the primary source for identifying the initial phishing email.
- ✗
Firewall logs
Why it's wrong here
Firewall logs show network connections allowed or denied based on IP addresses and ports. They might show command-and-control traffic after infection, but they do not record the content of emails or attachments. They would not directly reveal that a phishing email with a malicious attachment was the initial vector, only subsequent network activity.
- ✓
Email gateway logs
Why this is correct
Email gateway logs record all inbound and outbound email messages, including sender, recipient, subject, and attachment details. If the adversary used a phishing email with a malicious attachment, the gateway logs would show the delivery of that email, possibly with attachment names and hashes. This is the most direct evidence of the initial infection vector, allowing responders to trace the email back to the sender and identify other recipients.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.