Courseiva

GIAC Certified Forensic Analyst (GCFA) — Questions 76–150

292 questions total · 4pages · All types, answers revealed

Page 1

Page 2 of 4

Page 3
76
Multi-Selecthard

An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)

Select 2 answers
A.The process's token has been modified to include SeDebugPrivilege.
B.The process's primary image memory region is not backed by the file on disk that its path indicates.
C.The process has a thread whose start address lies outside any legitimate loaded module.
D.The process has a working set larger than the system average.
E.The process has a large number of handles open to named pipes.
AnswersB, C

Process hollowing replaces the legitimate image with malicious code, so the in-memory image no longer matches the on-disk executable. Detecting a primary image region that is unbacked or whose contents differ from the file at the recorded path is a core indicator. This artifact alone is highly suggestive when combined with other anomalies.

Why this answer

Process hollowing unmaps or overwrites the original image and injects replacement code, so the primary image region loses its legitimate file backing and threads often start in unbacked memory. Observing both an unbacked primary image and a thread starting outside known modules forms a coherent, high-confidence pattern. Pipe handles, token privilege changes, and working set size are unrelated to the hollowing technique.

Exam trap

The trap here is treating any single anomaly as proof of hollowing, when the technique is best confirmed by combining image-backing and thread-start anomalies.

77
MCQmedium

A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?

A.The process is a legitimate service host that was terminated and its EPROCESS is lingering in pool memory before being freed.
B.The process is a child of a protected process and is intentionally excluded from the active process list by Windows security features.
C.The process is a zombie process that has been reaped by its parent but its EPROCESS remains in memory due to a handle leak.
D.The process is hidden from the active process list due to direct kernel object manipulation (DKOM) unlinking its EPROCESS from the PsActiveProcessHead list.
AnswerD

DKOM rootkits often unlink a malicious process's EPROCESS from the doubly linked list pointed to by PsActiveProcessHead, hiding it from tools that rely on that list. Pool scanning (psscan) traverses pool tags to find EPROCESS objects regardless of list membership, so it detects the hidden process. The absence of the process in pslist but presence in psscan is a classic indicator of DKOM-based process hiding.

Why this answer

The discrepancy between psscan and pslist where a process appears in pool scanning but not in the active list is a hallmark of DKOM-based process hiding. Rootkits unlink the EPROCESS from the active process list to evade detection by tools that walk that list. Pool scanning finds the structure directly in memory, revealing the hidden process.

This is a fundamental technique in memory forensics for detecting stealthy malware.

Exam trap

The trap here is assuming that a process missing from pslist but present in psscan is merely a terminated process, when the lack of an ExitTime and the rootkit context indicate deliberate DKOM unlinking.

78
MCQmedium

An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?

A.windows.pslist
B.windows.cmdline
C.windows.netscan
D.windows.malfind
AnswerD

The malfind plugin scans process memory for regions that are both executable and writable, and that do not map to a file on disk. It then displays the start address of threads within those regions, which is a strong indicator of injected code. This directly addresses the requirement to find threads starting outside legitimate modules.

Why this answer

The malfind plugin is designed to detect hidden or injected code in memory by identifying memory regions that are both writable and executable and that lack a corresponding file on disk. It also reports the start address of threads within those regions. This makes it the correct choice for finding threads that start outside of legitimate modules, which is a common indicator of process injection or fileless malware.

Exam trap

The trap here is assuming that a process listing plugin like pslist will reveal injected code, when in fact malfind is needed to inspect memory protections and thread start addresses.

79
Multi-Selectmedium

An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)

Select 2 answers
A.Prefetch files for USBSTOR.SYS
B.Registry key: HKLM\SYSTEM\CurrentControlSet\Enum\USB
C.Setupapi.dev.log
D.Windows Event Log: Microsoft-Windows-DriverFrameworks-UserMode/Operational
E.NTFS $MFT
AnswersC, D

Setupapi.dev.log records device installation and driver setup events, including USB devices. It can contain the device's vendor and product IDs, serial number, and timestamps of when the device was first connected. This makes it a valuable artifact for corroborating USB connection, especially when USBSTOR is cleared.

Why this answer

Setupapi.dev.log and the Microsoft-Windows-DriverFrameworks-UserMode/Operational event log both record USB device installation and connection events with timestamps and device identifiers. These artifacts can provide evidence of a USB device even if the USBSTOR registry key has been cleared, making them essential for corroboration.

Exam trap

The trap here is relying solely on the USBSTOR registry key, which can be cleared by anti-forensic tools or simply not present in some cases, while overlooking other logs that record device installation and connection.

80
MCQmedium

What is the primary purpose of the $LogFile in NTFS?

A.To track user login history.
B.To prevent filesystem corruption.
C.To store backup copies of files.
D.To record all file access logs.
AnswerB

The $LogFile ensures atomic updates to metadata. By logging transactions before applying them, the NTFS driver can restore the volume to a consistent state following an unexpected power loss or system failure, which is the core requirement for modern, reliable file system operation.

Why this answer

The $LogFile is essential for maintaining NTFS consistency. It records all metadata changes before they are committed, allowing the system to recover from crashes by rolling back or completing interrupted operations. While the $LogFile is circular and does not store user data, its entries can often reveal the order of operations, helping an investigator reconstruct the sequence of events leading up to a system compromise.

Exam trap

Candidates often assume the $LogFile is intended for user activity tracking or auditing, failing to recognize its technical purpose as a filesystem consistency mechanism for crash recovery.

81
MCQmedium

When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?

A.To identify all running processes.
B.To find the current thread context.
C.To map virtual addresses to physical pages.
D.To reset kernel-mode security policies.
AnswerB

The KPCR stores the pointer to the currently executing thread for a specific core. By locating the KPCR in memory, an analyst can determine exactly what the processor was executing at the time the dump was taken, which is crucial for analyzing live malware execution and suspicious kernel threads.

Why this answer

The KPCR is a structure containing critical processor-specific information, including the current thread and CPU state. It is vital for forensic analysts because it serves as the anchor for finding the current thread of execution on each core. Understanding the KPCR helps analysts reconstruct the execution context, which is essential for identifying which threads were running at the moment of capture, especially during complex multi-threaded attacks.

Exam trap

Candidates often confuse the KPCR with the EPROCESS structure, incorrectly assuming it tracks process-level metadata rather than the low-level processor state and current thread context required by the kernel.

82
MCQeasy

An analyst is examining a Windows system and needs to determine when a USB mass storage device was last connected. Which registry artifact should be examined to find the device's first and last connection times?

A.The NTUSER.DAT hive under Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
B.The SECURITY hive under Policy\Secrets
C.The SOFTWARE hive under Microsoft\Windows\CurrentVersion\Uninstall
D.The SYSTEM hive under CurrentControlSet\Enum\USBSTOR
AnswerD

The USBSTOR key in the SYSTEM hive records USB mass storage devices and, within each device instance, the Properties subkey holds timestamps such as the first and last connection times. This makes it the correct artifact for determining when a USB device was last connected to the system.

Why this answer

USB mass storage devices are enumerated under CurrentControlSet\Enum\USBSTOR in the SYSTEM hive, and each device instance includes a Properties subkey with timestamps for first and last connection. Examining that key therefore provides the device identity and the connection timing needed to establish when the device was last attached to the system.

Exam trap

The trap here is choosing MountPoints2 for USB timing, when that key reflects per-user mount history rather than the device's first and last connection timestamps.

83
MCQeasy

Which NTFS master file table (MFT) record contains metadata about the MFT itself?

A.MFT Record 0
B.MFT Record 1
C.MFT Record 5
D.MFT Record 255
AnswerA

Record 0 is defined in the NTFS specification as the $MFT. It stores the metadata entries for the file system structure itself. This enables the operating system to bootstrap the driver and understand the layout of all subsequent files, directories, and internal system structures stored on the volume.

Why this answer

In NTFS, the MFT is treated as a file, and its metadata is stored within its own entry. Record 0 is reserved specifically for the MFT. This recursive structure is fundamental to the NTFS architecture, allowing the system to locate the MFT at boot time and parse the rest of the file system efficiently during startup processes.

Exam trap

Test-takers often guess record 1 or record 5, confusing the root directory or standard system files with the actual MFT metadata record itself.

84
MCQmedium

When analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?

A.Run dialog commands
B.Windows Explorer navigation paths
C.Recently opened documents
D.External device connection history
AnswerB

TypedPaths records the history of directory paths the user manually typed into the File Explorer address bar. This provides a direct record of the user's navigational intent, which is particularly useful for identifying access to sensitive directories that are not typically visible through standard menu-based browsing.

Why this answer

The 'TypedPaths' key is a goldmine for investigators as it stores the absolute paths that a user has manually entered into the Windows Explorer address bar. This artifact is highly reliable for proving user intent to access specific directories, including hidden folders or external media paths. By documenting where the user navigated, an analyst can build a compelling case regarding unauthorized file exploration that occurred outside of normal GUI clicking behavior.

Exam trap

Candidates often confuse TypedPaths with 'RecentDocs' or 'ShellBags', failing to distinguish that TypedPaths specifically records strings entered into the address bar, not just general folder access history.

85
MCQhard

An organization discovers that an attacker is using 'Living off the Land' (LotL) binaries to execute malicious code. Why are LotL attacks particularly difficult to detect in an enterprise environment?

A.The tools are specifically designed by attackers to bypass security.
B.They operate entirely in memory and leave no file system artifacts.
C.They utilize trusted system processes that are frequently used by administrators.
D.The attacker encrypts the binaries so antivirus cannot scan them.
AnswerC

LotL attacks abuse legitimate tools such as PowerShell or WMI that are already trusted by the OS and security software. Since administrators use these same tools for daily tasks, it is difficult to identify which executions are malicious without advanced behavioral analysis that correlates multiple logs and process metadata.

Why this answer

LotL attacks utilize legitimate, pre-installed system tools like PowerShell, WMI, or Certutil to execute malicious payloads. Because these tools are trusted and frequently used for legitimate administrative tasks, they often bypass traditional signature-based antivirus or allowlisting solutions. Detecting these requires sophisticated behavioral analysis, such as looking for anomalous command-line flags, unusual process ancestry, or unexpected execution patterns, which are significantly harder to differentiate from routine administrative activity compared to detecting known malicious malware binaries.

Exam trap

Many candidates focus on the 'maliciousness' of the binary itself rather than the context of the execution. The trap is assuming that the binary is inherently blocked, ignoring that LotL tools are legitimate and trusted.

86
MCQmedium

Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?

A.They automatically decrypt all files for easier analysis.
B.They provide a comprehensive view by integrating metadata from multiple sources.
C.They eliminate the need to preserve original forensic images.
D.They ensure all files are permanently deleted from the disk.
AnswerB

By combining registry, log, and file system artifacts, these tools provide a complete narrative. This integration allows the analyst to see the causal relationship between events, such as a process execution event in a log file followed by a file modification in the NTFS MFT, which is crucial for reconstruction.

Why this answer

Super-timelines aggregate data from diverse sources including file systems, event logs, registry hives, and application-specific artifacts into a single chronological view. Manual timestamp collection is limited to file system metadata, which often fails to capture the 'why' behind an event. By aggregating disparate data, analysts can correlate file changes with system events, providing a much richer, holistic context that is necessary to solve complex, multi-stage security incidents.

Exam trap

Candidates mistakenly believe that manual timestamp collection provides the same contextual depth as super-timelines, missing the crucial correlation with registry and event logs.

87
MCQmedium

A forensic analyst is creating a timeline from a Windows 10 workstation using fls and mactime from The Sleuth Kit. The analyst notices that the bodyfile contains entries with timestamps that appear to be off by several hours compared to the wall-clock time the incident was reported. The system is known to be set to UTC in the BIOS. Which action best ensures the timeline is correctly aligned for reporting?

A.Apply the Windows time zone setting from the registry to convert the timestamps to local time before analysis.
B.Discard the bodyfile and regenerate it using a tool that automatically converts timestamps to the analyst's local time zone.
C.Adjust each timestamp by the offset observed in the bodyfile until the timeline matches the incident report time.
D.Verify the time zone configuration and document whether timestamps are stored in UTC, then normalize all timeline entries to UTC for comparison.
AnswerD

NTFS stores timestamps in UTC, so normalizing the timeline to UTC removes ambiguity and ensures consistency across sources. Documenting the system's time zone configuration captures the context needed to interpret any user-facing times and supports a defensible report.

Why this answer

NTFS timestamps are recorded in UTC, so a timeline built from them should be normalized to UTC to avoid ambiguity and to allow correlation with other UTC-based sources such as event logs. Documenting the system's time zone configuration provides context for user-facing times but does not change the underlying UTC values. Arbitrary adjustment of timestamps undermines the integrity of the timeline.

Exam trap

The trap here is assuming that timestamps must be converted to local time to be useful, when UTC normalization is the defensible choice.

88
MCQhard

During a forensic investigation of a Windows 10 system, an analyst observes that a file's $STANDARD_INFORMATION creation timestamp is 2020-01-01 10:00:00, while its $FILE_NAME creation timestamp is 2020-01-01 10:00:05. The system time zone is UTC-5. The analyst also notes that the file's $STANDARD_INFORMATION modification timestamp is 2020-01-01 10:00:00. What is the most likely explanation for the 5-second difference between the creation timestamps?

A.The file was timestomped, and the attacker set the $STANDARD_INFORMATION creation time to match the modification time.
B.The 5-second difference indicates that the file was copied from another volume, and the $FILE_NAME creation time was updated to the copy time.
C.The 5-second difference is due to the file system tunneling feature, which preserves the original creation time from a deleted file with the same name.
D.The 5-second difference is normal because $STANDARD_INFORMATION and $FILE_NAME timestamps are updated at different times during file creation.
AnswerD

During file creation, the $STANDARD_INFORMATION timestamps are set first, and the $FILE_NAME timestamps are set slightly later. A small difference of a few seconds is common and not indicative of tampering. This is the most likely explanation for the observed 5-second gap.

Why this answer

A small difference of a few seconds between $STANDARD_INFORMATION and $FILE_NAME creation timestamps is normal and occurs because the two sets of timestamps are written at slightly different times during file creation. It is not necessarily an indicator of timestomping or other manipulation.

Exam trap

The trap here is assuming that any discrepancy between $STANDARD_INFORMATION and $FILE_NAME timestamps indicates malicious activity, when in fact minor differences are expected due to normal system behavior.

89
MCQmedium

During a forensic examination of an NTFS volume, an analyst notices that a file's $STANDARD_INFORMATION timestamps show a modification time of 2023-04-01 10:00:00, but the $FILE_NAME timestamps show a modification time of 2023-03-15 14:30:00. The file is not a system file and has not been renamed. What is the most likely explanation for this discrepancy?

A.The file was copied from another volume, preserving the $FILE_NAME timestamps but updating the $STANDARD_INFORMATION timestamps.
B.The file's $STANDARD_INFORMATION timestamps were modified by a timestomping tool, while the $FILE_NAME timestamps remained unchanged.
C.The file was moved within the same volume, which updates $STANDARD_INFORMATION but not $FILE_NAME timestamps.
D.The file system is corrupted, causing inconsistent timestamps between attributes.
AnswerB

Timestomping tools often target $STANDARD_INFORMATION timestamps because they are easily accessible via user-mode APIs. They may not update $FILE_NAME timestamps, especially if the file was not renamed. This creates a discrepancy where $STANDARD_INFORMATION shows a later modification time than $FILE_NAME. In this scenario, the file was not renamed, so $FILE_NAME timestamps should reflect the original modification time, making timestomping the most likely explanation.

Why this answer

Timestomping tools often alter $STANDARD_INFORMATION timestamps without updating $FILE_NAME timestamps, especially when the file is not renamed. This creates a discrepancy where $STANDARD_INFORMATION shows a later modification time than $FILE_NAME. Since the file was not renamed, the $FILE_NAME timestamps likely reflect the original modification time, indicating tampering.

Exam trap

The trap here is assuming that any timestamp discrepancy indicates file system corruption, when in fact timestomping is a common anti-forensic technique that targets specific attributes.

90
MCQhard

During an investigation of a compromised Windows Server 2019, an analyst extracts the ShimCache (AppCompatCache) from the SYSTEM registry hive. The analyst needs to determine which executable was present on the system but may have been deleted. Which artifact within the ShimCache entry provides the best indication of file existence and last modification time?

A.The SHA256 hash of the executable
B.The execution flag and run count
C.The process ID and parent process ID
D.The file path and last modified timestamp
AnswerD

The ShimCache entry contains the full file path and, on Windows 8 and later, a last modified timestamp from the file's $STANDARD_INFORMATION attribute. This timestamp indicates when the file was last modified, not when it was executed. However, the presence of a path in ShimCache confirms the file existed on the system at some point, which is valuable for identifying deleted executables. This makes it the correct choice for determining file existence and last modification time.

Why this answer

ShimCache entries include the file path and, on Windows 8+, a last modified timestamp from the file's $STANDARD_INFORMATION attribute. This timestamp helps determine when the file was last modified, and the presence of the path confirms the file existed. Execution flags and run counts are not part of ShimCache; those are in UserAssist or Prefetch.

Process IDs and hashes are also not stored in ShimCache.

Exam trap

The trap here is confusing ShimCache with artifacts like UserAssist or AmCache that track execution or hashes; ShimCache only records file paths and last modified times.

91
Multi-Selecthard

An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)

Select 2 answers
A.$LogFile
B.$UsnJrnl
C.$Secure
D.$Bitmap
E.$Boot
AnswersA, B

$LogFile records metadata transactions before they are committed to the $MFT. After a sudden power loss, it can contain recent file creation, deletion, and renaming operations that were not yet flushed. Parsing it allows reconstruction of file system changes that occurred just before the crash.

Why this answer

$LogFile and $UsnJrnl both record metadata operations. $LogFile is a write-ahead log that captures transactions before they are committed to the $MFT, making it valuable after an unexpected shutdown. $UsnJrnl provides a persistent change journal that records file and directory modifications. Together they can reconstruct recent activity that may not be present in the $MFT.

Exam trap

The trap here is assuming that allocation maps like $Bitmap or security files like $Secure contain change history, when only $LogFile and $UsnJrnl record metadata operations.

92
MCQeasy

An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?

A.The $LogFile transaction log
B.The $MFT file and its unallocated MFT entry records
C.The $UsnJrnl:$J change journal
D.The $Bitmap allocation file
AnswerB

Deleted file metadata often remains in unallocated MFT entries until overwritten. Parsing the $MFT, including unallocated entries, allows recovery of $STANDARD_INFORMATION and $FILE_NAME timestamps for deleted files, enabling their inclusion in the timeline even though the file content is gone.

Why this answer

Unallocated MFT entries preserve the $STANDARD_INFORMATION and $FILE_NAME attributes of deleted files until those entries are reused. By parsing the $MFT, including slack and unallocated records, an analyst can recover the four MACB timestamps for files that no longer exist in the active file system, which is essential for a complete forensic timeline.

Exam trap

The trap here is assuming that deleted files leave no timestamp evidence once their MFT entry is marked as unallocated, when in fact the record content often persists until reuse.

93
MCQmedium

An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?

A.The process is a legitimate kworker that is part of a user-space threading library, which can create network sockets for inter-process communication.
B.The process is a legitimate kworker that has been infected by a rootkit, so the network socket is actually owned by a hidden malicious process.
C.The process is a legitimate kernel worker that has been temporarily repurposed by the system for network load balancing.
D.The process is likely a malicious backdoor masquerading as a kernel thread, and further analysis should include checking its executable path and parent process.
AnswerD

Attackers often name malicious processes to mimic legitimate system processes like kworker to avoid detection. A kworker process listening on a port is a strong indicator of a backdoor. The analyst should use tools like 'ls -l /proc/1234/exe' to find the executable and 'ps -fp 1234' to see the parent, which can reveal the malware's origin.

Why this answer

A process named kworker listening on a network port is anomalous because legitimate kworker threads are kernel threads and do not open sockets. This strongly suggests a malicious process masquerading as a kernel thread. The analyst should investigate the executable path and parent process to confirm and identify the malware.

Exam trap

The trap here is assuming that because the process name matches a legitimate kernel thread, it must be benign, ignoring the fact that kernel threads never listen on network ports.

94
MCQmedium

An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?

A.The session was established using a valid SSH public key, indicating successful key-based authentication from 10.20.30.40.
B.The session was established through a brute-force password attack that succeeded after many failures.
C.The session was established through a reverse shell initiated by a malicious payload on the server.
D.The session was established through SSH agent forwarding from an untrusted host, which is why no password prompt was logged.
AnswerA

The 'Accepted publickey' message and the RSA SHA256 fingerprint confirm that SSH key-based authentication succeeded. The subsequent PAM session-open entry confirms a shell or session was established. With no preceding failed password attempts from that IP, this pattern is consistent with legitimate key-based access — though the analyst should still verify the key belongs to the expected user and that the source IP is trusted.

Why this answer

The 'Accepted publickey' line with an RSA SHA256 fingerprint shows sshd validated the client's key, and the subsequent pam_unix session-open confirms a login session. The absence of prior 'Failed password' entries from that IP rules out a brute-force narrative. Key-based access is the correct interpretation, subject to verifying the key's ownership and the trustworthiness of the source address.

Exam trap

The trap here is confusing the absence of a password prompt with suspicious behavior, when 'Accepted publickey' is the explicit sshd log marker for successful key-based authentication.

95
MCQeasy

Which artifact is the primary location for finding 'Shellbag' data, which tracks user folder access history?

A.SYSTEM hive
B.NTUSER.DAT hive
C.SOFTWARE hive
D.SAM hive
AnswerB

Shellbags are stored in the user-specific NTUSER.DAT registry hive. They track folder access, directory view settings, and navigation history. This registry key is the authoritative source for reconstructing a user's interaction with the file system, providing key evidence of which folders were browsed during the period of interest.

Why this answer

Shellbags are stored in the NTUSER.DAT registry hive. They provide an invaluable record of which folders a user has opened and the specific view settings applied to those folders. This artifact is critical for forensic investigations because it proves user presence in specific directories, which can be used to link a user account to the staging of malicious files or the browsing of sensitive data during an incident.

Exam trap

Candidates often incorrectly guess the SYSTEM hive or SOFTWARE hive, forgetting that Shellbags are user-specific artifacts stored within the individual user's NTUSER.DAT registry file.

96
Multi-Selectmedium

A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)

Select 2 answers
A.Volume Shadow Copy snapshots
B.$MFT entries, including unallocated records
C.$UsnJrnl:$J change journal
D.$LogFile transaction log
E.$Bitmap allocation file
AnswersB, C

$MFT entries contain the $STANDARD_INFORMATION and $FILE_NAME attributes with creation, modification, access, and entry modification timestamps. Unallocated entries can preserve timestamps for deleted files until reused, making the $MFT essential for both creation and deletion timeline events.

Why this answer

The $MFT, including unallocated entries, provides timestamps for files that existed or were deleted. The $UsnJrnl:$J logs file system changes with timestamps, capturing creation and deletion events. Together, they offer a robust foundation for a file system timeline, allowing analysts to correlate timestamps and change records.

Exam trap

The trap here is overlooking unallocated $MFT entries, which can still contain timestamps for deleted files, or assuming the $LogFile is a primary timeline source.

97
MCQmedium

A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?

A.The file C:\Windows\System32\Tasks\<TaskName> in the Task Scheduler store
B.The Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders key in the SOFTWARE hive
C.The Microsoft\Windows NT\CurrentVersion\Winlogon key's Shell value in the SOFTWARE hive
D.The Software\Microsoft\Windows\CurrentVersion\Run key in the NTUSER.DAT hive
AnswerA

The Task Scheduler stores each task as an XML file under C:\Windows\System32\Tasks, named after the task path. That XML contains the Actions (the executable and arguments) and Triggers, including logon triggers, so examining it directly reveals the suspicious binary and the logon trigger configured for persistence.

Why this answer

Scheduled tasks are defined as XML files in the Task Scheduler store under C:\Windows\System32\Tasks, and each file includes the task's Triggers and Actions. A logon trigger with an action launching a suspicious binary is exactly the persistence configuration described, so inspecting that XML file directly reveals both the executable and the trigger that causes it to run at logon.

Exam trap

The trap here is confusing registry autostart locations such as Run or Winlogon Shell with scheduled tasks, when only the Task Scheduler store holds task actions and triggers.

98
MCQhard

During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?

A.The file was likely moved or renamed after its last content modification, causing the $FILE_NAME timestamps to update while $STANDARD_INFORMATION times remained older.
B.The file's timestamps were definitely manipulated with a timestomping tool that altered $STANDARD_INFORMATION.
C.The file was accessed by an antivirus scanner, which updated the $FILE_NAME access time and left $STANDARD_INFORMATION modification time unchanged.
D.The file was created by the operating system during installation, and the newer $FILE_NAME times reflect the last time it was backed up.
AnswerA

A move or rename within the same volume updates the $FILE_NAME timestamps but does not necessarily update $STANDARD_INFORMATION. The observed gap where $FILE_NAME times are newer than $STANDARD_INFORMATION times is consistent with such an operation and provides a plausible timeline sequence.

Why this answer

When a file is moved or renamed within an NTFS volume, the $FILE_NAME attribute timestamps are updated to the time of the operation, while $STANDARD_INFORMATION timestamps may remain unchanged. This produces a pattern where $FILE_NAME times are newer than $STANDARD_INFORMATION times. While timestomping can also create discrepancies, it typically makes $STANDARD_INFORMATION appear older, and without additional indicators the move or rename explanation is better supported by the specific pattern observed.

Exam trap

The trap here is jumping to timestomping whenever the two attribute timestamp sets disagree, without considering legitimate rename or move operations.

99
MCQhard

An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?

A.$UsnJrnl:$J stream
B.$FILE_NAME attribute within the file's MFT record
C.$INDEX_ROOT attribute of the parent directory
D.$Bitmap metadata file
AnswerB

The $FILE_NAME attribute in an MFT record stores the file's name and a reference to the parent directory's MFT entry. Even after deletion, if the MFT record is not overwritten, this attribute remains and can be used to reconstruct the full path by following the parent reference. This is the primary artifact for recovering the name and location of a deleted file when the MFT entry is intact.

Why this answer

The $FILE_NAME attribute in the MFT record contains the file's name and a reference to its parent directory's MFT entry. By parsing this attribute and then locating the parent MFT entry, an analyst can reconstruct the full path. Other artifacts like $Bitmap or $UsnJrnl may provide supporting information but do not directly contain the full path.

Exam trap

The trap here is assuming that the USN Journal or $Bitmap contains the full path, when in fact the $FILE_NAME attribute in the MFT record is the authoritative source for the file's name and parent reference.

100
MCQhard

An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?

A.It stores the complete file path and SHA-256 hash of every document opened by the user.
B.It maintains a list of recently accessed files and folders, which can indicate user browsing activity and potential data exfiltration.
C.It records the most recently opened documents and folders, including the last access time and the application used to open them.
D.It tracks the execution time of applications associated with the opened documents.
AnswerB

RecentDocs keys under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs store lists of recently opened documents and folders, organized by file extension. They provide evidence of user activity, such as which files were accessed, and can help establish a timeline of user interactions. This is valuable for identifying potential data exfiltration or unauthorized access to sensitive files.

Why this answer

RecentDocs provides a list of recently accessed files and folders, which is valuable for understanding user activity and potential data exfiltration. It does not include hashes, execution times, or last access timestamps, so the correct interpretation is that it indicates browsing activity and accessed documents.

Exam trap

The trap here is assuming that RecentDocs contains timestamps or hashes, when it actually only lists recently accessed file and folder names, typically organized by extension.

101
MCQmedium

During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?

A.Prefetch files, checking the last execution time of explorer.exe
B.NTUSER.DAT registry hive, examining the LastWrite time of the user's shell bags
C.Security event log, filtering for Event ID 4624 with Logon Type 2 or 10
D.SRUM database, querying the Network Usage table for active connections
AnswerC

Event ID 4624 in the Security log records successful logons and includes the Logon Type field. Type 2 indicates interactive logon at the console, while Type 10 indicates RemoteInteractive (RDP). These events provide the account name, timestamp, and logon type, directly answering who was logged on interactively and when, assuming the log has not been cleared or overwritten.

Why this answer

Security event log entries with Event ID 4624 and Logon Type 2 or 10 provide definitive records of interactive and RemoteInteractive logons, including the account name, timestamp, and logon type. Other artifacts like shell bags, SRUM, or Prefetch may show user activity but lack the direct logon session details required to answer who was logged on and when.

Exam trap

The trap here is assuming that any user activity artifact, such as shell bags or Prefetch, can substitute for explicit logon event records when determining interactive logon sessions.

102
MCQmedium

An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?

A.Run the script directly in a production environment to see its effect.
B.Use a base64 decoder to convert the command string to plaintext.
C.Search for the command in the Windows Update history.
D.Check the local BIOS/UEFI logs for the command execution.
AnswerB

Decoding the base64 string reveals the original PowerShell code, which is essential for understanding the intended actions. This allows the analyst to identify malicious logic, such as network connections or file system changes, that the attacker was attempting to hide from traditional security monitoring tools and administrative logs.

Why this answer

Base64 encoded PowerShell commands are a common tactic to bypass signature-based detection. The analyst must extract the encoded string, decode it using standard utilities like CyberChef or PowerShell itself, and then perform static analysis on the resulting script. This process is vital to understand the attacker's intent, such as identifying hidden C2 downloaders, persistence scripts, or data collection commands that were otherwise obscured from basic text-based log searches.

Exam trap

Candidates frequently try to read encoded PowerShell command strings manually without decoding the Base64 payload first, wasting time on obfuscated syntax.

103
MCQeasy

While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?

A.An attacker renamed a malicious binary to 'sshd' to blend in with legitimate processes.
B.The sshd binary was updated by the package manager during an unattended upgrade.
C.The sshd process is a legitimate child spawned by a user's SSH session.
D.The system experienced a crash and systemd restarted sshd through a recovery shell.
AnswerA

Legitimate sshd is spawned by systemd and immediately opens its listening socket on port 22. A process named sshd but parented by bash and holding no listener was almost certainly started manually by an interactive shell, which is the hallmark of an attacker renaming a tool to masquerade as a system daemon while it performs other actions such as beaconing or credential collection.

Why this answer

On Linux, parent process and socket state are strong discriminators of legitimacy. A real sshd is started by systemd, which makes PID 1 its parent, and it binds port 22. A process carrying the sshd name but parented by bash and holding no listening socket could not be performing the SSH service role, so the most supportable conclusion is that a binary was renamed to mimic sshd.

Exam trap

The trap here is trusting the process name alone, when on Linux the parent PID and bound sockets are what distinguish a real daemon from a masqueraded binary.

104
MCQhard

During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?

A.HKLM\SYSTEM\CurrentControlSet\Services
B.HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
C.HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
D.HKCU\Software\Microsoft\Windows\CurrentVersion\Run
AnswerA

This registry key contains subkeys for each installed service. Each service subkey includes values such as ImagePath, which points to the executable, and Start, which defines when the service starts. Examining this key will reveal the malicious service's configuration, including the path to the malicious executable.

Why this answer

Windows services are configured in the registry under HKLM\SYSTEM\CurrentControlSet\Services. Each service has its own subkey containing values like ImagePath, which specifies the executable to run, and Start, which determines the start type. Investigating this key allows you to identify malicious services and their executables.

Exam trap

The trap here is confusing service persistence with Run key persistence, but services are stored in the SYSTEM hive under CurrentControlSet\Services, not in the SOFTWARE hive's Run keys.

105
MCQmedium

Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?

A.The Windows Registry SAM hive.
B.Windows LNK files and Jump Lists.
C.System event logs (Event ID 7045).
D.The browser cache database.
AnswerB

LNK files and Jump Lists are specifically designed to track recent user activity. They record the path, access time, and volume information for files opened by the user. These artifacts remain on the system after the source file is deleted, making them invaluable for reconstructing past user behavior during an investigation.

Why this answer

Shell items, specifically LNK files and Jump Lists, maintain metadata about user file interactions. When a user opens a file, the OS creates these artifacts, which persist even if the target file is removed. This makes them essential for identifying user intent and proving that a malicious file was not only present but was actively accessed by the user, providing critical evidence for attribution.

Exam trap

Candidates often confuse LNK files with registry keys or general prefetch files, failing to recognize that shell items specifically track direct user interactions and file paths even after target deletion.

106
MCQmedium

An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?

A.windows.netscan
B.windows.malfind
C.windows.pslist
D.windows.cmdline
AnswerB

windows.malfind scans for memory regions with suspicious characteristics, such as executable permissions and no corresponding file on disk, which are typical of code injection. It helps identify injected code even when the process image is missing. This plugin is specifically designed to detect hidden or injected code in process memory, making it the correct choice for this scenario.

Why this answer

The windows.malfind plugin is designed to detect injected code by scanning for memory regions that are executable but not backed by a file on disk. In this scenario, the process's image path is missing, which is a red flag for injection. Malfind would reveal such anomalies, helping the analyst confirm the presence of injected code.

Other plugins like pslist, netscan, and cmdline do not perform this type of memory analysis.

Exam trap

The trap here is assuming that any plugin that lists processes or network connections can detect code injection, when only malfind specifically analyzes memory regions for suspicious characteristics.

107
MCQhard

You are reviewing a Windows 10 host for evidence of process execution. A suspect binary was deleted from disk, but you need to prove it actually ran. Which artifact provides the strongest evidence that the specific executable was launched, independent of any prefetch or shimcache entries?

A.A Prefetch file (.pf) containing the binary's name and run count in C:\Windows\Prefetch
B.The Amcache.hve entry containing the binary's SHA-1 hash and path
C.Security event 4688 with the New Process Name field populated for the binary
D.The AppCompatCache (ShimCache) entry for the binary in the SYSTEM hive
AnswerC

Event ID 4688 is written to the Security log when a new process is created, and with process creation auditing enabled it records the New Process Name and often the command line. It is generated at the moment of execution and does not depend on Prefetch or ShimCache, making it the strongest independent proof that the specific executable ran.

Why this answer

Event ID 4688 is generated by the Windows auditing subsystem at the instant a process is created, capturing the new process image path and, when command-line auditing is enabled, the full command line. Unlike ShimCache or Amcache, which can be populated by file presence or scanning, 4688 only appears when execution occurs, so it independently proves the suspect binary was launched.

Exam trap

The trap here is treating file-observation artifacts such as ShimCache or Amcache as proof of execution, when they can record files that were merely present or scanned.

108
Multi-Selecthard

Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?

Select 3 answers
A.Utilizing WMI (Windows Management Instrumentation) to execute remote commands.
B.Installing a custom kernel-mode rootkit for persistence.
C.Using Bitsadmin to download external payloads.
D.Executing scripts via PowerShell to gather system information.
E.Running a custom C++ backdoor compiled on the target.
AnswersA, C, D

WMI is a powerful administrative framework that is frequently abused for remote code execution and lateral movement. Because WMI operations are essential for system management, they often blend in with normal administrative traffic, allowing attackers to maintain persistence and control without installing custom, easily detectable malware binaries.

Why this answer

LotL techniques leverage legitimate, pre-installed administrative tools to perform malicious actions. Because these binaries are signed and expected to be present in the environment, traditional endpoint protection often ignores them. Attackers use these tools for discovery, lateral movement, and execution, effectively hiding their activity in the noise of normal system administration tasks, which makes them highly effective for stealthy operations within a compromised network.

Exam trap

Candidates often include non-LotL tools like custom malware or unauthorized hacking tools. LotL specifically refers to using pre-installed, trusted system binaries like PowerShell, WMI, or Bitsadmin for malicious purposes.

109
MCQeasy

A forensic analyst is examining a Windows 10 system and wants to determine which USB storage devices have been connected to the machine. The analyst has access to the registry. Which registry key should the analyst examine to find a list of USB devices that have been connected, including vendor and product IDs?

A.HKLM\SOFTWARE\Microsoft\Windows Portable Devices\Devices
B.HKLM\SYSTEM\CurrentControlSet\Enum\USB
C.HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR
D.HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR\Enum
AnswerC

The USBSTOR key under Enum stores information about USB mass storage devices that have been connected to the system. Each subkey corresponds to a device and includes the vendor, product, and revision, as well as a serial number if available. This is the primary artifact for determining USB storage device connection history.

Why this answer

The USBSTOR registry key under HKLM\SYSTEM\CurrentControlSet\Enum is the authoritative location for USB mass storage device connection history. It records the vendor, product, and revision of each device, along with a serial number when available. Other USB-related keys either include non-storage devices or lack the detailed storage-specific information needed to identify connected USB drives.

Exam trap

The trap here is confusing the general USB enumeration key with the USBSTOR key, which is specifically for mass storage devices and contains the vendor and product details.

110
MCQmedium

Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?

A.Prefetch files
B.USBSTOR Registry Key
C.ShellBags
D.SRUM (System Resource Usage Monitor)
AnswerB

The USBSTOR key in the SYSTEM hive acts as a central repository for all USB device connections. It stores the vendor, product ID, and serial number of the device. Even after the device is disconnected, this entry remains, providing a permanent record of the hardware's interaction with the system.

Why this answer

The 'USBSTOR' registry key in the SYSTEM hive is the definitive artifact for tracking USB device history. It records the vendor, model, and unique serial number of every USB device ever connected. This is critical for forensic investigations involving data exfiltration, as it allows the investigator to prove that a specific physical device was present, regardless of whether the user deleted the device drivers or emptied the recycle bin.

Exam trap

Candidates often look at the 'MountPoints2' key instead of 'USBSTOR', failing to realize that MountPoints2 is user-specific and can be cleared, whereas USBSTOR is system-wide and more persistent.

111
Multi-Selecthard

A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)

Select 2 answers
A.PowerShell operational log event ID 4104 containing an encoded script that decodes to a reflective loader
B.Injected code in the memory of a legitimate process, such as explorer.exe, visible through memory forensics
C.An entry in the ShimCache (AppCompatCache) for a malicious binary
D.A newly created service with a binary path pointing to a suspicious executable in C:\Windows\Temp
E.A prefetch file for a known malicious executable on disk
AnswersA, B

Event ID 4104 captures script block content, and an encoded script that decodes to a reflective loader is a classic fileless technique. Reflective loaders execute code directly in memory without writing to disk. This artifact provides evidence of the initial execution vector and the malicious payload, and when combined with memory injection evidence, strongly confirms an active fileless attack.

Why this answer

Fileless malware operates by injecting code into memory and often uses scripts like PowerShell to load payloads reflectively without writing executables to disk. Finding injected code in a legitimate process's memory via memory forensics, combined with a PowerShell script block log showing an encoded reflective loader, provides strong evidence of an active fileless attack. The other artifacts—prefetch, service creation with a binary, and ShimCache—all indicate disk-based execution, which is inconsistent with a fileless attack.

Exam trap

The trap here is selecting artifacts that show any malicious activity, such as prefetch or ShimCache, without considering that fileless attacks specifically avoid leaving such disk-based traces.

112
MCQhard

When analyzing the $LogFile in NTFS, what is the significance of the undo and redo operations recorded in the transaction logs for timeline reconstruction?

A.They enable the recovery of deleted file content.
B.They provide a sequential record of metadata changes.
C.They are only used by the OS for chkdsk recovery.
D.They only record changes to the root directory index.
AnswerB

The $LogFile acts as a transaction journal. By replaying the redo and undo operations, an analyst can reconstruct the exact sequence of metadata changes for a specific file. This is crucial for verifying if a file's metadata was changed multiple times in rapid succession, which standard MFT analysis might miss.

Why this answer

The $LogFile is a circular buffer that records metadata transactions to ensure file system consistency. Redo operations replay actions to restore state after a crash, while undo operations revert changes. For a forensic analyst, these logs are vital because they capture the 'before' and 'after' state of MFT entries, providing a granular history of file system modifications that occur faster than standard logging frequencies.

Exam trap

Test-takers frequently mistake $LogFile transaction logs for standard application logs or event logs, missing their true role as low-level metadata consistency buffers.

113
Multi-Selectmedium

A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)

Select 2 answers
A.windows.pslist
B.windows.handles
C.windows.psscan
D.windows.cmdline
E.windows.pstree
AnswersA, C

windows.pslist walks the active process list (PsActiveProcessHead) to enumerate processes that were active at the time of capture. It provides a list of processes with their PIDs, PPIDs, and other details, but it may miss processes that have terminated or are hidden.

Why this answer

windows.pslist enumerates processes from the active process list, while windows.psscan scans memory for process structures, which can uncover terminated or hidden processes. Using both provides a more comprehensive view of processes that were running or had recently terminated. The other plugins either rely on the same active list or serve different purposes.

Exam trap

The trap here is assuming that pstree provides an independent process enumeration method; it actually uses the same active process list as pslist and does not scan for hidden processes.

114
MCQmedium

An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?

A.pslist
B.handles
C.malfind
D.pstree
AnswerC

Malfind specifically scans for VAD nodes marked as PAGE_EXECUTE_READWRITE that lack an associated mapped file. This is the primary signature of injected code or hollowed processes where attackers have manually allocated memory to house malicious payloads. It provides the necessary visibility into anomalous memory protections within target processes.

Why this answer

The malfind plugin is the standard tool for identifying injected code by scanning for memory segments with Execute/Read/Write permissions that are not backed by a file on disk. This is a critical step in volatile memory analysis because malware often uses process hollowing to hide its execution flow within legitimate system processes. Comparing VAD protections helps confirm the anomaly, which is a hallmark of sophisticated persistent threats evading standard file-based detection.

Exam trap

Examinees often confuse basic process enumeration plugins with memory injection detectors, failing to utilize specialized tools that evaluate VAD permissions and unbacked memory regions.

115
MCQmedium

An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?

A.An interactive user logged into the local console, triggering default privilege escalation assignments.
B.A scheduled batch job executed locally using stored credentials without generating network authentication traffic.
C.An adversary performed lateral movement using stolen administrative credentials over the network to access administrative shares.
D.A service account automatically restarted following a system crash, initiating local service control manager requests.
AnswerC

Logon Type 3 signifies a network authentication session, and Event ID 4672 explicitly records the assignment of special privileges to new logon sessions. Attackers routinely leverage network shares and administrative credentials to pivot across internal enterprise endpoints seamlessly.

Why this answer

This specific sequence indicates a network logon successfully authenticating an administrative user, frequently observed during lateral movement via SMB or PsExec. Understanding this pattern allows analysts to differentiate authorized administrative maintenance from credential-based attacks, mapping directly to attacker tactics in enterprise environments.

Exam trap

Candidates often misinterpret internal non-routable subnet traffic as benign local communication, ignoring the significance of Logon Type 3 followed immediately by Event ID 4672.

116
MCQmedium

During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?

A.The lsass.exe process is a masquerading implant because its parent should always be services.exe.
B.The lsass.exe process has been injected with a credential-dumping payload because its PID is not a multiple of four.
C.The lsass.exe process must have been relocated from its original directory because the System32 copy is reserved for svchost.exe.
D.The lsass.exe process appears consistent with a normal Windows host; the parent and image path match expected behavior.
AnswerD

Both the parent process (winlogon.exe) and the image path (C:\Windows\System32\lsass.exe) match the expected configuration for LSASS on a Windows 10 workstation. A masquerading lsass.exe would typically show a non-system path or an unexpected parent. These artifacts therefore support a benign classification, though corroborating evidence such as digital signature or handle analysis should still be reviewed.

Why this answer

Legitimate LSASS on Windows is launched by winlogon.exe from C:\Windows\System32\lsass.exe, and the captured parent-child relationship and image path both match that baseline. Because neither attribute deviates from expected behavior, the artifacts support a normal-host classification. Analysts should still corroborate with signature and handle inspection, but these particular memory artifacts do not indicate compromise.

Exam trap

The trap here is assuming that any lsass.exe parent other than services.exe indicates masquerading, when in fact winlogon.exe is the expected parent on a Windows workstation.

117
MCQhard

What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?

A.To index directory contents.
B.To store extended file permissions.
C.To reference attributes stored in other MFT records.
D.To track file deletion history.
AnswerC

When a file's attributes exceed the size of one MFT record, the $ATTRIBUTE_LIST attribute is created. It acts as a pointer map, listing the location and type of attributes held in additional MFT records, ensuring that the operating system can still access the complete metadata set for the file.

Why this answer

The $ATTRIBUTE_LIST attribute is used when an MFT record is too small to hold all of a file's attributes. By storing a list of references to other MFT records, NTFS allows a single file to span multiple records. This is a crucial concept for analysts because it means that critical evidence, such as timestamps or data runs, might be hidden in secondary MFT records outside the primary entry.

Exam trap

Candidates often assume an MFT record is always self-contained, failing to account for the $ATTRIBUTE_LIST which allows files to span multiple MFT records when metadata is too large.

118
MCQmedium

During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?

A.windows.psscan
B.windows.netscan
C.windows.pstree
D.windows.cmdline
AnswerA

windows.psscan scans physical memory for EPROCESS structures using pool tag scanning, which can reveal processes that are not linked in the active process list due to rootkit unlinking or other hiding techniques. This directly addresses the need to find hidden processes by comparing against windows.pslist. It is the correct plugin for detecting discrepancies that indicate process hiding.

Why this answer

windows.psscan uses pool tag scanning to locate EPROCESS structures in memory, which can uncover processes that have been unlinked from the active process list by rootkits or other hiding techniques. By comparing its output with windows.pslist, an analyst can identify discrepancies indicating hidden processes. The other plugins either rely on the active list or serve different purposes, such as command-line retrieval or network connection enumeration.

Exam trap

The trap here is assuming that windows.pstree, which shows parent-child relationships, would automatically reveal hidden processes, but it only displays processes already present in the active list.

119
MCQhard

You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?

A.This is normal service account behavior and no further review is needed.
B.This proves credential theft via Pass-the-Hash against the service account.
C.This is a network logon using NTLM that warrants correlation with source host and account baseline.
D.This indicates a successful interactive console logon by an attacker.
AnswerC

Logon Type 3 with the NTLM package means the credentials were presented over the network rather than interactively, and the absence of 4672 special-privilege assignment or 4648 explicit-credential use suggests a straightforward authenticated network access. Because NTLM bypasses Kerberos policy controls, the record must be correlated with the account's normal source hosts to determine whether the authentication is anomalous.

Why this answer

Logon Type 3 identifies a network logon, and the NTLM authentication package means the session did not use Kerberos. That alone is not proof of compromise, but it is a meaningful indicator that must be baselined against the account's normal source hosts, logon patterns, and downstream privilege events before any conclusion about credential theft or lateral movement is drawn.

Exam trap

The trap here is treating Logon Type 3 with NTLM as automatic proof of Pass-the-Hash, when it is only a network authentication that requires corroborating evidence.

120
Multi-Selecthard

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)

Select 2 answers
A.windows.handles
B.windows.netscan
C.windows.dlllist
D.windows.psscan
E.windows.pslist
AnswersD, E

windows.psscan scans physical memory for process objects by using pool tag scanning, which can find processes that are unlinked from the active process list. It is effective for detecting hidden processes because it does not rely on the operating system's linked list. This plugin is essential when a rootkit has unlinked a process to hide it.

Why this answer

To detect hidden processes, analysts compare the output of windows.pslist, which walks the active process list, with windows.psscan, which scans physical memory for process objects using pool tag scanning. Discrepancies where psscan finds processes not in pslist indicate hidden processes, often due to rootkit activity. The other plugins do not provide this comparison and are used for different forensic purposes.

Exam trap

The trap here is thinking that any plugin that lists processes can detect hidden ones, but only the combination of pslist and psscan reveals discrepancies caused by unlinking.

121
MCQhard

During a response to an incident involving a web shell, you find that the attacker is using custom encoding to bypass WAF signatures. What is the best forensic approach to identify all impacted web files?

A.Run a regex-based search for common web shell function names.
B.Perform a file integrity check against the original source code base.
C.Analyze WAF logs to identify all requests that resulted in 200 OK codes.
D.Examine the access logs for all requests containing encoded characters.
AnswerB

Comparing the current web directory against a trusted source control baseline is the most effective way to detect unauthorized modifications. By identifying every added, deleted, or modified file, you can isolate the web shells regardless of their obfuscation, as any unauthorized change is inherently suspicious in a production environment.

Why this answer

When attackers use custom encoding to hide web shells, signature-based WAF detections are ineffective. The most robust method is to perform a differential analysis of the web application's codebase against a known-good baseline, such as the original source control repository. By automatically highlighting differences, you can identify injected code blocks that don't match authorized files, regardless of how they are encoded or obfuscated by the attacker during the injection process.

Exam trap

Candidates often choose WAF log analysis, assuming the WAF will catch all attempts. However, custom encoding bypasses signatures, making file-level integrity checking the only reliable way to detect injected code.

122
Multi-Selectmedium

During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)

Select 2 answers
A.Immediately shut down the system to prevent further malicious activity and then create a forensic image of the hard drive.
B.Use a write blocker when connecting the hard drive to a forensic workstation to create a bit-for-bit image.
C.Run 'netstat -ano' to record active network connections and associated process IDs.
D.Capture the contents of physical memory (RAM) using a forensic tool before shutting down the system.
E.Disconnect the workstation from the network before capturing any volatile data to prevent data leakage.
AnswersC, D

Running netstat captures current network connections and listening ports, along with the process IDs. This is valuable for identifying command-and-control connections and lateral movement. It is a quick, non-intrusive command that should be run early in the collection process. The output can be correlated with process listings and memory analysis to understand the attacker's network activity. It is a best practice to document these connections before they change.

Why this answer

Capturing physical memory and recording active network connections are both essential for preserving volatile evidence. Memory contains running processes, encryption keys, and injected code, while netstat reveals current network activity that may indicate command-and-control or lateral movement. These steps should be performed before any action that alters the system state, such as shutdown or disconnection.

Exam trap

The trap here is thinking that shutting down the system or disconnecting it from the network is a safe first step, but that destroys volatile evidence.

123
MCQmedium

An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?

A.Analyzing the process environment block (PEB)
B.Verifying the SSDT function pointers
C.Enumerating all running threads
D.Scanning for file system changes in the MFT
AnswerB

The SSDT is the dispatch table used by the kernel for system calls. Rootkits frequently overwrite these pointers to redirect execution to their own malicious code. Validating that all SSDT pointers reside within the legitimate kernel memory space is the standard method for detecting kernel-level hooks.

Why this answer

Kernel hooks are a common rootkit tactic used to intercept system calls and hide malicious files, network connections, or processes. By performing integrity checks on the System Service Descriptor Table (SSDT) or the Interrupt Descriptor Table (IDT), an analyst can identify function pointers that point outside the expected range of the kernel's memory space, which is a clear indicator of malicious redirection and rootkit activity.

Exam trap

Candidates frequently suggest examining user-mode process lists or standard disk logs to detect kernel rootkits, missing the fact that kernel hooks operate below standard monitoring visibility.

124
MCQeasy

An analyst is examining a Windows 10 system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log should be examined to find the most recent interactive logon event?

A.Application Event Log, Event ID 1000
B.Security Event Log, Event ID 4624 with Logon Type 2
C.Security Event Log, Event ID 4634
D.System Event Log, Event ID 6005
AnswerB

Event ID 4624 in the Security log records successful logon attempts. Logon Type 2 indicates an interactive logon at the console. By filtering for Event ID 4624 and Logon Type 2, an analyst can identify the most recent interactive logon. This is the correct source for determining when a user last logged on interactively.

Why this answer

Security Event ID 4624 with Logon Type 2 records interactive logons at the console. By examining the most recent such event, an analyst can determine when a user last logged on interactively. System Event ID 6005 relates to service startup, Application Event ID 1000 to application crashes, and Security Event ID 4634 to logoffs, none of which answer the question.

Exam trap

The trap here is confusing logon and logoff events or looking in the wrong log; interactive logons are recorded as Event ID 4624 with Logon Type 2 in the Security log.

125
MCQmedium

An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unchanged. What does this specific combination of inode timestamp changes typically indicate in a Linux environment?

A.The file contents were modified via a redirected write operation from a standard unprivileged user shell script.
B.The file permissions, ownership, or extended attributes were altered without modifying the underlying data blocks.
C.A background process read the file contents while the file system was mounted with strictatime options enabled.
D.The file was accessed and executed in memory using a shared library mapping that suppressed standard kernel logging.
AnswerB

On ext4, ctime records inode metadata changes, so a recent ctime with unchanged atime and mtime indicates metadata such as permissions, ownership or extended attributes were modified without touching file content or access times, consistent with anti-forensic or administrative tampering.

Why this answer

In ext4 file systems, the inode change time (ctime) updates whenever the inode metadata is modified, even if the file content (mtime) or access time (atime) remains untouched. Recognizing that metadata-only operations like permission changes or ownership transfers update ctime independently is critical for distinguishing between content tampering and permission hardening.

Exam trap

Test-takers often assume that any file modification timestamp change includes the data blocks (mtime), forgetting that metadata-only operations alter the ctime independently.

126
MCQeasy

In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?

A.To store the process execution priority.
B.To map virtual memory ranges for a process.
C.To log all network connections made.
D.To secure the process against buffer overflows.
AnswerB

The VAD tree tracks all virtual memory allocations, providing the kernel with the necessary information to handle page faults and enforce memory access permissions. Forensic tools analyze the VAD tree to reconstruct the process memory map, which is necessary to identify injected code, unbacked regions, and suspicious memory attributes.

Why this answer

The VAD tree is a kernel structure used by the memory manager to keep track of the virtual memory ranges allocated to a process. It is essential for forensic analysts because it defines the memory map of a process, including which areas are executable, read-only, or writable. This structure is critical for identifying memory-resident threats that attempt to hide their presence by manipulating memory permissions to execute malicious code.

Exam trap

Candidates often confuse the VAD tree with the Page Table or physical memory structures, incorrectly attributing the mapping of virtual address spaces to lower-level hardware memory management components.

127
MCQmedium

An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?

A.It records the exact UTC execution time for all files in the SYSTEM hive.
B.Entries are only populated when the UserAssist key is enabled in the registry.
C.It tracks file path and last modification time for potential application compatibility.
D.It is stored within the NTUSER.DAT hive for each individual user profile.
AnswerC

Shimcache stores the file path and the last modified time of the executable. This helps the OS determine if a file is compatible. For forensics, this artifact is essential for identifying executable files that existed on the system, even if those files were subsequently deleted by an attacker.

Why this answer

The Shimcache, or AppCompatCache, tracks file metadata to ensure application compatibility. Crucially, it tracks file paths and last modified times but does not natively record the exact execution timestamp of an application. It is primarily used to identify files that were present on the system and potentially executed, serving as a critical indicator of software presence during an investigation into lateral movement or malware persistence on a Windows endpoint.

Exam trap

Candidates incorrectly believe the Shimcache provides a precise execution timestamp, leading them to misinterpret the 'Last Modified' file metadata as the moment the malicious file was run.

128
MCQmedium

An organization is deploying an EDR solution to improve incident response capabilities. What is the most critical factor to consider when configuring EDR policies for a production environment?

A.Ensuring the EDR agent is configured to delete all suspicious files automatically.
B.Balancing security posture with the risk of operational impact.
C.Forcing all EDR logs to be stored in the cloud for infinite retention.
D.Disabling all other security tools to prevent agent conflict.
AnswerB

Production environments require high availability. An EDR policy that is too aggressive might block legitimate processes, leading to critical service downtime. Balancing security with operational stability through testing and monitoring is the most important factor to ensure the EDR adds value without negatively impacting core business productivity.

Why this answer

EDR policies must be carefully tuned to prevent false positives that can lead to system instability, such as inadvertently blocking critical business processes or causing performance degradation. In production, an 'alert-only' mode is often implemented first to gather data and validate the impact. Without proper testing and tuning, a overly aggressive EDR configuration can disrupt legitimate operations, causing more damage to business productivity than the threats the EDR is intended to mitigate.

Exam trap

Candidates frequently choose aggressive blocking postures, underestimating the business disruption caused by false positives when deploying security controls in sensitive production environments.

129
Multi-Selecthard

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)

Select 2 answers
A.The presence of a driver object with no corresponding file on disk in the drivers directory.
B.The SSDT is found to be writable in memory, whereas it should be read-only in a clean system.
C.The ntoskrnl.exe module in memory has a different hash than the known-good version from the same Windows build.
D.The KPCR (Kernel Processor Control Region) for each CPU shows a different value for the IDT base address.
E.The System Service Descriptor Table (SSDT) entries point to addresses outside the ntoskrnl.exe module.
AnswersB, E

In a clean Windows system, the SSDT is typically protected as read-only after initialization. If the SSDT is writable, it suggests that a rootkit has modified memory protections to allow hooking. This is a strong indicator of SSDT hooking because the rootkit must disable write protection to alter the table.

Why this answer

SSDT hooking involves redirecting system service calls by modifying the SSDT, which normally points to functions within ntoskrnl.exe. Two key indicators are SSDT entries pointing outside ntoskrnl.exe and the SSDT being writable when it should be read-only. Other artifacts like missing driver files or IDT variations are not specific to SSDT hooking, and a modified kernel hash indicates patching rather than hooking.

Exam trap

The trap here is confusing general rootkit indicators with specific evidence of SSDT hooking, such as assuming any kernel modification or missing driver file proves SSDT manipulation.

130
MCQmedium

During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?

A.The connections are proof of a network-based attack and should be reported as a confirmed incident.
B.The connections indicate that the memory image is corrupted and should be reacquired.
C.The connections prove that a rootkit is hiding a running process from the process list.
D.The connections are likely residual artifacts from a terminated process, and the examiner should correlate timestamps and process IDs to confirm.
AnswerD

windows.netscan parses network structures that may persist after a process exits, especially if the process object has not been fully reclaimed. Residual connections from terminated processes are common and should be validated by correlating process IDs, timestamps, and related artifacts rather than immediately concluding malicious activity. This cautious correlation approach avoids false positives.

Why this answer

windows.netscan can surface network structures that outlive their owning process, so missing process entries alongside established connections often reflect terminated processes rather than hidden malware. Correlating process IDs, timestamps, and other artifacts is the proper next step. Claiming rootkit activity, image corruption, or a confirmed attack from this observation alone is premature and unsupported.

Exam trap

The trap here is assuming any mismatch between network connections and the process list indicates active hiding, when stale structures from exited processes are a common benign cause.

131
Multi-Selecthard

An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?

Select 3 answers
A.Enable Credential Guard on all workstations and servers.
B.Disable NTLM authentication and force Kerberos usage.
C.Implement Local Administrator Password Solution (LAPS).
D.Increase the minimum password length requirement to 20 characters.
E.Regularly scan for and remove all local user accounts.
AnswersA, B, C

Credential Guard uses virtualization-based security to isolate secrets in a protected container. By preventing access to the LSA process memory, it stops attackers from extracting NTLM hashes or Kerberos tickets, which are the fundamental building blocks for Pass-the-Hash and Pass-the-Ticket attacks, significantly hardening the host against lateral movement.

Why this answer

Pass-the-Hash exploits the way NTLM stores password hashes in memory. By limiting the scope of where privileged accounts can authenticate and restricting the use of legacy protocols like NTLM in favor of Kerberos, organizations can significantly shrink the attack surface. Implementing Credential Guard provides an additional layer of hardware-based isolation that prevents the extraction of these hashes from memory, effectively neutralising the primary mechanism that attackers rely on for lateral movement within a domain.

Exam trap

Candidates often pick only one or two options and miss the requirement for a comprehensive approach. They may forget LAPS, which is critical for preventing lateral movement via local admin credential reuse.

132
MCQmedium

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

A.The command line contains -k netsvcs
B.The process path is C:\Windows\System32\
C.The ParentPID value
D.The process name is svchost.exe
AnswerC

Svchost.exe is a critical system process that should always be spawned by services.exe. If the PPID does not match the process ID of services.exe, it strongly suggests that the process is a masquerading binary or has been launched by an unauthorized actor, even if the path appears correct.

Why this answer

The process name 'svchost.exe' is a common target for masquerading. While the path seems correct, the Parent Process ID (PPID) is the critical indicator. A legitimate svchost.exe should always be spawned by 'services.exe'.

If the PPID 567 points to an unexpected process, such as an explorer.exe or a temporary file, it indicates a potential process masquerading or injection attempt, warranting immediate deep-dive analysis of that parent process.

Exam trap

Candidates often assume that a process named 'svchost.exe' is legitimate if the file path is correct, failing to verify the parent process that spawned it.

133
MCQmedium

An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?

A.Security.evtx
B.System.evtx
C.WMI-Activity/Operational.evtx
D.Application.evtx
AnswerC

This log file specifically captures WMI events, including requests, queries, and process creation triggered by the WMI service. It is the most direct artifact for identifying malicious WMI activity, providing the necessary evidence to confirm that an attacker utilized this specific management interface for remote code execution.

Why this answer

The 'Microsoft-Windows-WMI-Activity/Operational' log is the primary source for tracking WMI interactions. WMI is frequently abused for lateral movement because it allows for stealthy, authenticated command execution. By reviewing these specific operational logs, analysts can correlate WMI provider activity with process creation events, confirming whether a remote actor utilized WMI to launch malicious processes on the target system without needing an interactive shell session.

Exam trap

Candidates often check general security logs (4688) which show the process but lack the context of the remote WMI invocation that triggered the execution.

134
Multi-Selecthard

You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)

Select 2 answers
A.The $FILE_NAME attribute stores the file's original path when the file was moved, and the parent directory reference points to the original directory.
B.The $FILE_NAME attribute includes a namespace field that indicates whether the name is in the POSIX, Win32, or DOS namespace.
C.Each $FILE_NAME attribute corresponds to a hard link to the file, and the parent directory reference points to the directory containing that link.
D.The $FILE_NAME attribute is updated whenever the file's content is modified, reflecting the last modification time.
E.The $FILE_NAME attribute can be resident or non-resident depending on the length of the filename.
AnswersB, C

The $FILE_NAME attribute has a namespace field that specifies the naming convention: POSIX (0), Win32 (1), DOS (2), or Win32 & DOS (3). This field helps determine the format of the filename, such as whether it is a short 8.3 name or a long name. It is a standard part of the attribute.

Why this answer

$FILE_NAME attributes represent hard links; each link has a parent directory reference pointing to the directory containing the link. The namespace field indicates the naming convention used. These attributes are always resident and their timestamps update on rename or move, not content modification.

Multiple $FILE_NAME attributes therefore indicate multiple hard links, and their parent references help reconstruct directory structure.

Exam trap

The trap here is assuming that $FILE_NAME attributes preserve historical paths or that they are updated on content modification, when they actually reflect current hard links and static timestamps.

135
Multi-Selectmedium

An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)

Select 2 answers
A.System event log for Event ID 7045 (service installation)
B.Prefetch files for PSEXESVC.exe
C.Amcache.hve for entries related to PsExec.exe
D.SRUM database for network connections by PsExec.exe
E.Security event log for Event ID 4624 with Logon Type 3
AnswersA, B

PsExec installs a temporary service named PSEXESVC on the target system. The installation of this service is recorded in the System event log with Event ID 7045, which includes the service name, image path, and service type. This provides strong evidence that PsExec was used, especially if the service name matches PSEXESVC.

Why this answer

PsExec usage on a target system leaves two key artifacts: the installation of the PSEXESVC service, recorded in the System event log as Event ID 7045, and the execution of PSEXESVC.exe, which generates a Prefetch file. These directly indicate PsExec activity. Other artifacts like network logons or Amcache entries are less specific and may be caused by other activities.

Exam trap

The trap here is focusing on generic network logon events or Amcache entries, which are not specific to PsExec, instead of the distinctive service installation and Prefetch artifacts that PsExec creates.

136
Multi-Selecthard

An organization is deploying an EDR solution across a hybrid environment. Which TWO of the following tasks are critical for ensuring effective incident response visibility?

Select 2 answers
A.Excluding all antivirus-flagged files from the EDR scanning scope.
B.Configuring full-stack telemetry collection across all managed endpoints.
C.Defining and testing automated containment playbooks for high-severity alerts.
D.Disabling kernel-mode auditing to improve endpoint performance metrics.
E.Restricting data retention to 24 hours to comply with privacy regulations.
AnswersB, C

Full-stack telemetry—including process creation, network connections, registry changes, and file system modifications—is essential for reconstructing an attacker's timeline. Without this data, responders lack the context needed to identify lateral movement or command-and-control communication, rendering the EDR tool ineffective at providing a comprehensive picture of the incident's scope.

Why this answer

Successful EDR deployment requires both technical configuration and operational integration. Ensuring comprehensive coverage across all endpoints prevents blind spots where attackers can hide, while defining automated response playbooks allows the IR team to scale their efforts during high-velocity incidents. These tasks are foundational to reducing mean time to respond, as they ensure high-fidelity telemetry is available and actionable, allowing for rapid containment of threats before they escalate across the enterprise network.

Exam trap

Candidates focus exclusively on threat intelligence feeds or endpoint isolation tools, ignoring the foundational requirement for comprehensive telemetry collection and tested playbooks.

137
MCQmedium

An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?

A.The SRUM database entry for svchost.exe
B.The $MFT record for the svchost.exe file
C.The digital signature of the svchost.exe file
D.The Prefetch file for svchost.exe
AnswerC

Checking the digital signature verifies whether the executable is signed by Microsoft and has not been tampered with. A legitimate svchost.exe should be signed by Microsoft and reside in System32. If the signature is invalid or missing, it indicates a masquerading attempt, directly addressing the analyst's need to verify integrity and origin.

Why this answer

Verifying the digital signature of the executable is the most direct way to confirm whether svchost.exe is the legitimate Microsoft binary. A valid signature from Microsoft indicates the file is authentic and unmodified, while an invalid or missing signature suggests masquerading. Other artifacts like Prefetch, $MFT, and SRUM provide contextual information but do not verify integrity and origin.

Exam trap

The trap here is relying on execution artifacts like Prefetch or SRUM to prove legitimacy, when only signature verification can confirm the binary's authenticity.

138
MCQhard

A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?

A.The processes were created by the SYSTEM account, which often indicates that a service or scheduled task spawned them; this could be normal or malicious depending on the process.
B.The processes were created by a user who logged on interactively, as indicated by the logon ID starting with 0x3, which denotes interactive logons.
C.The processes were created by a user with a randomly assigned logon ID, which suggests the system is using logon session isolation for security.
D.The processes were created by a user with a well-known logon ID, which is typical for system services and indicates no malicious activity.
AnswerA

Logon ID 0x3e7 is the well-known logon ID for the SYSTEM account (NT AUTHORITY\SYSTEM). Processes with this logon ID are typically spawned by services, scheduled tasks, or other SYSTEM-level components. While this is normal for many system processes, attackers who gain SYSTEM privileges will also generate events with this logon ID. Therefore, the analyst must correlate the process name and command line to determine if it is suspicious.

Why this answer

The logon ID 0x3e7 is a well-known identifier for the SYSTEM account in Windows. Process creation events with this logon ID indicate that the process was spawned under the SYSTEM context, which is common for services and scheduled tasks. However, because attackers often escalate to SYSTEM, the analyst must examine the process name, command line, and parent process to determine if the activity is malicious.

The logon ID alone is not sufficient to declare benign or malicious.

Exam trap

The trap here is assuming that any process with logon ID 0x3e7 is automatically benign because it is SYSTEM, when in fact attackers frequently operate under SYSTEM and such events require deeper scrutiny.

139
MCQeasy

A forensic analyst is examining a Windows 10 system and finds a prefetch file named `CMD.EXE-1234ABCD.pf`. The analyst wants to determine the last time the program was executed. Which timestamp in the prefetch file should the analyst use?

A.The file's $STANDARD_INFORMATION Modified timestamp in the MFT.
B.The file's $FILE_NAME Created timestamp in the MFT.
C.The last run time stored internally in the prefetch file's header.
D.The volume's $LogFile entry for the prefetch file.
AnswerC

Prefetch files contain internal metadata, including a last run timestamp in the file header. This timestamp is updated when the program is executed and is a more direct indicator of execution than the file system timestamps. Tools like PECmd parse this internal timestamp, which is why it is the preferred artifact for determining last execution time.

Why this answer

Prefetch files store an internal last run timestamp in their header, which is updated each time the program executes. Forensic tools like PECmd extract this timestamp, making it the most direct evidence of last execution. File system timestamps such as $STANDARD_INFORMATION Modified can correlate but are not as precise for execution time.

Exam trap

The trap here is using the prefetch file's file system Modified timestamp instead of parsing the internal last run timestamp, which is specifically designed to record execution.

140
MCQmedium

What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?

A.It stores user credentials for encrypted sessions.
B.It records transaction metadata for crash recovery.
C.It keeps a copy of all deleted file contents.
D.It is used by BitLocker to verify volume integrity.
AnswerB

The $LogFile ensures that NTFS can recover from crashes by logging metadata transactions. Investigators can parse this to see recent file system changes that were in progress. This makes it a high-value artifact for reconstructing activity that occurred immediately preceding a system crash or intentional shutdown.

Why this answer

The $LogFile is a circular buffer that records metadata operations before they are finalized. When a system crashes or loses power, the NTFS driver uses the $LogFile upon reboot to replay or undo incomplete transactions, ensuring volume consistency. For investigators, it provides a window into the state of the filesystem immediately before the crash, potentially recovering records of files modified just before the power failure.

Exam trap

Candidates often confuse the $LogFile with the Event Logs or the USN Journal, mistakenly assuming it contains application-level activity logs rather than low-level filesystem transaction metadata used for crash recovery.

141
MCQmedium

Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?

A.SYSTEM hive; tracking system services
B.NTUSER.DAT hive; tracking user-initiated program execution
C.SOFTWARE hive; tracking installed application paths
D.SECURITY hive; tracking authentication logs
AnswerB

UserAssist is located in the NTUSER.DAT hive, which is unique to each user profile on the system. It tracks the programs the user launches via the Windows shell, recording execution counts and timestamps, making it the primary artifact for identifying user-driven activity during an investigation.

Why this answer

UserAssist is stored within the NTUSER.DAT hive of the specific user account. Its value lies in the rotational cipher (ROT13) used for the data, which, once decrypted, reveals a list of GUI-based programs executed by the user. This artifact is invaluable for linking specific user activity to the execution of malicious tools, providing proof that the user was behind the keyboard during the incident, as opposed to an automated system service.

Exam trap

Candidates often confuse the UserAssist hive location with the SYSTEM hive or assume it tracks all system-wide background services, ignoring its specific focus on user-initiated GUI program execution.

142
MCQhard

During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?

A.Analyzing the memory image for service records using a tool like Volatility.
B.Running a full antivirus scan with updated signatures.
C.Enumerating services using the Services.msc GUI.
D.Comparing the output of 'sc query' with the service list from the registry.
AnswerA

Memory forensics tools like Volatility can parse kernel data structures to enumerate services directly from memory, bypassing any API hooks or registry modifications. By examining the service list in memory, you can detect services that are hidden from user-mode APIs. This is the most effective method for identifying rootkit-hidden services, as it relies on the actual state of the system rather than potentially compromised interfaces.

Why this answer

Rootkits often hook user-mode APIs to hide their presence, so tools that rely on those APIs (like Services.msc or sc query) may not show the malicious service. Memory forensics tools like Volatility directly parse kernel structures such as the service list, which are harder for rootkits to manipulate without causing instability. This allows detection of services that are hidden from standard interfaces.

Antivirus may also be bypassed, making memory analysis the most effective approach.

Exam trap

The trap here is trusting user-mode API outputs like Services.msc or sc query, which can be manipulated by a rootkit.

143
MCQmedium

What is the primary function of the $LogFile in NTFS when reconstructing a timeline?

A.To store the actual file content data for quick retrieval
B.To track all user-level file access and modification events
C.To record metadata transactions for file system integrity
D.To store backup copies of the Master File Table
AnswerC

The $LogFile is an essential component for NTFS transaction integrity. For a forensic investigator, it provides a chronologically ordered record of metadata changes. This allows for the reconstruction of recent events, enabling the identification of file system activity even if the standard MFT record has been updated or overwritten.

Why this answer

The $LogFile is a circular buffer that records metadata transactions for the file system. It is invaluable for forensic analysts because it captures recent changes to the file system, including those that might not yet be committed to the MFT. By parsing the $LogFile, investigators can recover evidence of file creations, deletions, or renames that occurred shortly before an incident, providing a granular view of recent activity that might otherwise be lost.

Exam trap

Candidates often mistake the $LogFile for a user activity log, failing to realize it is a low-level file system integrity mechanism that tracks metadata transactions, not user actions.

144
MCQmedium

An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?

A.To bypass the need for multi-factor authentication on local machines.
B.To gain unrestricted control over the entire domain and its resources.
C.To encrypt the Active Directory database for ransomware demands.
D.To hide their tracks by clearing the Windows Event logs globally.
AnswerB

Domain Admin is the most powerful privilege level in a Windows domain. By successfully compromising this group, an attacker inherits the ability to perform any action on any object within the domain, effectively giving them complete authority to manipulate resources, settings, and user access across the whole enterprise network.

Why this answer

Targeting the Domain Admins group is the 'holy grail' for an attacker because it provides full control over the entire Active Directory domain. With these privileges, an attacker can disable security controls, create new accounts, exfiltrate sensitive data, and install persistent backdoors across all systems joined to the domain. This level of access effectively grants the attacker the ability to operate undetected and exert complete influence over the organization's enterprise infrastructure.

Exam trap

Candidates often confuse the goal of 'Domain Admins' targeting with specific technical outcomes like 'credential dumping' or 'data exfiltration', missing that these are simply intermediate methods to achieve the primary goal of total domain control.

145
MCQmedium

During an enterprise-wide incident response, a Windows workstation is suspected of being compromised by a threat actor who used a spear-phishing document. The machine is still powered on and the user is logged in. You need to capture volatile evidence in a forensically sound manner. Which of the following is the correct order of volatility for collecting evidence, from most volatile to least volatile?

A.Temporary file systems, disk, RAM, routing table, CPU registers and cache
B.CPU registers and cache, routing table, RAM, temporary file systems, disk
C.Disk, RAM, temporary file systems, routing table, CPU registers and cache
D.RAM, CPU registers and cache, disk, temporary file systems, routing table
AnswerB

This order correctly follows the RFC 3227 guidelines for order of volatility. CPU registers and cache are the most volatile, followed by routing tables, ARP cache, process table, kernel statistics, and memory. Temporary file systems and disk are less volatile. Collecting in this order minimizes loss of critical evidence that disappears when the system is powered down.

Why this answer

The order of volatility dictates that the most perishable evidence be collected first. CPU registers and cache change with every instruction, routing tables and ARP caches expire quickly, and RAM loses its contents on power-off. Temporary file systems and disk are comparatively persistent.

Following this sequence preserves the most fragile evidence before it is altered or destroyed by normal system activity or shutdown.

Exam trap

The trap here is assuming that RAM is always the most volatile component, when CPU registers and cache are even more volatile and are often overlooked.

146
MCQmedium

An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?

A.Perform a full disk imaging of the host immediately.
B.Execute an immediate reboot of the affected system.
C.Correlate the DNS query timestamps with socket ownership via netstat or EDR telemetry.
D.Flush the local DNS resolver cache on the host.
AnswerC

Mapping process IDs to remote network connections provides definitive proof of which executable is responsible for the beaconing. By comparing the process creation time and the socket initiation time, the analyst can identify the specific binary responsible for the traffic, which is a foundational step in host-based incident response.

Why this answer

Isolating the process behavior through network connection correlation allows the analyst to map the C2 traffic to a specific binary. Identifying the parent process and local socket ownership is essential to distinguish between legitimate background tasks and automated beaconing activity. This helps narrow the scope of the investigation by confirming the persistence mechanism and the specific threat actor communication pattern associated with the compromised host.

Exam trap

Candidates frequently jump to conclusions by analyzing DNS queries in isolation without correlating them with actual socket ownership or local process execution on the host.

147
MCQeasy

A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?

A.windows.dlllist
B.windows.modules
C.windows.handles
D.windows.pslist
AnswerB

windows.modules scans the kernel module list and reports loaded kernel modules, including drivers and their base addresses. This directly supports comparing loaded modules against a known-good baseline to detect unauthorized drivers. It is the appropriate Volatility 3 plugin for enumerating kernel modules from a Windows memory image, making it the correct choice here.

Why this answer

The windows.modules plugin is designed to enumerate loaded kernel modules from a Windows memory image, providing a list of drivers and their base addresses. This is essential for comparing against a known-good baseline to identify unauthorized or malicious kernel modules. The other plugins target process lists, DLLs within processes, or handles, none of which directly provide a system-wide kernel module enumeration.

Exam trap

The trap here is confusing process-level DLL enumeration with kernel module enumeration, as both involve loaded code but operate at different privilege levels and require different plugins.

148
MCQeasy

What is the primary role of the $MFTMirr file in NTFS?

A.To mirror all file contents.
B.To index all files in the system.
C.To provide a backup of the first MFT records.
D.To store encrypted file keys.
AnswerC

The $MFTMirr file acts as a protective mechanism, storing a copy of the first few entries in the MFT. This allows the system to recover essential boot and file system metadata if the beginning of the MFT is corrupted, ensuring the volume remains accessible for basic operations.

Why this answer

The $MFTMirr file contains a backup of the first few records of the Master File Table. This is vital for filesystem recovery if the primary MFT record gets corrupted. For forensic analysts, the $MFTMirr provides a fail-safe that confirms the structure of the MFT and can sometimes contain remnants of file metadata that are useful when the primary MFT record has been damaged or maliciously altered.

Exam trap

Students frequently mistake the $MFTMirr for a full backup of the entire filesystem rather than realizing it is specifically a safety copy of only the first few MFT records.

149
MCQmedium

During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?

A.Delete the IAM role immediately.
B.Attach an inline policy to deny all actions for the compromised role.
C.Change the password for the root user account.
D.Disable the entire cloud subscription or account.
AnswerB

Attaching a 'Deny All' policy is the most effective way to neutralize the compromised role instantly. Because explicit denies always override allows in IAM, the attacker loses the ability to execute any commands, while the role itself remains in the cloud configuration for forensic investigation and audit purposes.

Why this answer

In cloud environments, the most precise way to contain an identity-based attack is to apply an inline policy to the compromised role that explicitly denies all actions, or to revoke the active session tokens. By narrowing the scope of permissions or invalidating current credentials, responders can prevent the attacker from performing further unauthorized API calls while allowing legitimate, non-impacted services to continue functioning correctly within the environment.

Exam trap

Candidates often choose to delete the entire IAM role or disable the root account, causing catastrophic service outages rather than applying targeted containment.

150
MCQeasy

You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?

A.windows.cmdline
B.windows.registry.hivelist
C.windows.pslist
D.windows.info
AnswerD

windows.info reads the kernel's version information and other basic system details directly from the memory image. It displays the major and minor version, build number, service pack, and architecture, which are essential for selecting the correct symbol table or profile. This plugin is specifically designed to provide OS identification from memory, making it the correct choice.

Why this answer

To identify the operating system version and service pack from a memory image, you need a plugin that reads kernel version data. windows.info extracts this directly from the kernel structures in memory, providing the build number and service pack level. The other plugins focus on registry hives, process listing, and command lines, none of which directly report the OS version in a concise manner.

Exam trap

The trap here is thinking that the registry hivelist will give you the OS version quickly, when in fact you would need to parse the registry separately and it is not a direct memory analysis plugin for OS identification.

Page 1

Page 2 of 4

Page 3

All pages