Courseiva

GIAC Certified Forensic Analyst (GCFA) — Questions 151–225

292 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQmedium

An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?

A.The file content is stored in clusters outside the MFT and can be recovered by carving the volume
B.The file content is stored within the MFT record itself and may be recoverable if the record has not been overwritten
C.The file content is compressed and requires the $COMPRESSION attribute to be decoded
D.The file content is encrypted and requires the $LOGGED_UTILITY_STREAM attribute to be decrypted
AnswerB

A resident $DATA attribute means the file's content is small enough to fit inside the MFT record. When the file is deleted, the record is marked as free but the data remains until the record is reallocated. Therefore, the content may still be recoverable by parsing the MFT entry.

Why this answer

A resident $DATA attribute means the file's content is stored directly within the MFT record because it is small enough. After deletion, the record is marked free but the data persists until the record is reused. An examiner can parse the MFT entry to recover the content, provided the record has not been overwritten.

Exam trap

The trap here is confusing resident data with external cluster storage, leading an analyst to attempt carving instead of examining the MFT record itself.

152
MCQmedium

Which of these is the primary limitation of using a file system 'Birth' time as a definitive event marker?

A.It is not recorded in the MFT for small files
B.It is reset during file move or copy operations
C.It is only available on newer versions of Windows
D.It is protected from being read by forensic tools
AnswerB

Moving or copying a file creates a new entry in the file system, which results in a new birth timestamp. This destroys the original creation evidence, making the birth time useless for determining when the file first arrived on the system if it has been moved or copied by the attacker.

Why this answer

The 'Birth' time is highly vulnerable to being reset or changed during common file operations, such as moving or copying files to a new location or restoring from a backup. Because it does not represent the original, immutable creation of the file in the environment, it cannot be reliably used as a 'ground truth' for when an attacker first introduced the file to the system. Investigators must corroborate this with other evidence.

Exam trap

Candidates incorrectly assume 'Birth' time is an immutable record of when a file was first created, forgetting that copy operations frequently generate a new 'Birth' timestamp for the destination file.

153
MCQmedium

Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?

A.Identification
B.Containment
C.Recovery
D.Lessons Learned
AnswerC

Recovery is the phase where systems are restored, patches are applied, and security controls are validated to ensure the environment is safe for business operations. This step ensures that the root cause is addressed and that no residual access or persistence mechanisms remain that could allow the adversary to regain control.

Why this answer

The recovery phase is where the focus shifts from stopping the bleeding to restoring business operations securely. This involves verifying that all backdoors have been closed, credentials have been rotated, and systems are patched against the initial vulnerability used by the attacker. Without rigorous verification in this phase, the enterprise remains vulnerable to reinfection, as attackers often leave dormant persistence mechanisms that can be triggered if the remediation is not thorough.

Exam trap

Candidates often choose 'Remediation' or 'Eradication' as the phase for returning to a secure state. While those are involved, 'Recovery' is the formal phase defined by ensuring business operations are restored securely.

154
MCQeasy

During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?

A.The KDBG structure, because it stores the list of logged-on user sessions and their SIDs.
B.The EPROCESS block for winlogon.exe, because it stores the Security Identifier (SID) of the interactive user.
C.The token object referenced by explorer.exe, because its user SID identifies the interactively logged-on account.
D.The PEB of lsass.exe, because it caches the credentials of the interactive user in plaintext.
AnswerC

Explorer.exe runs in the interactive user's context, and its primary token contains the user SID of that account. Parsing the token from explorer.exe's EPROCESS in memory reveals the interactive user. This is a standard technique in memory forensics for attributing activity to a specific logged-on user when no other session artifacts are available.

Why this answer

The interactive user's identity is tied to the token of a process running in that user's session, such as explorer.exe. Extracting the token SID from explorer.exe's EPROCESS in the memory image confirms which account was interactively logged on. Other structures like KDBG or winlogon's EPROCESS do not directly hold the interactive user SID, making them unsuitable for this specific attribution.

Exam trap

The trap here is assuming that winlogon.exe or lsass.exe directly store the interactive user's SID in their process structures, when the reliable source is the token of a user-context process like explorer.exe.

155
MCQmedium

An analyst is investigating a Windows 10 system and finds a suspicious shortcut file in a user's Recent folder. The analyst wants to determine the full path of the target file and any command-line arguments used when the shortcut was created. Which artifact should the analyst examine?

A.The Windows Registry key: NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
B.The Prefetch file for explorer.exe
C.The jumplist AutomaticDestinations file
D.The .lnk file itself
AnswerD

The .lnk file (shortcut) contains a LinkTargetIDList and other structures that store the original target path, as well as command-line arguments if present. By parsing the .lnk file, the analyst can extract the full path and any arguments, making it the correct artifact for this purpose.

Why this answer

Shortcut (.lnk) files contain embedded structures that include the target path, working directory, command-line arguments, and other metadata. Parsing these files directly provides the most accurate and detailed information about the shortcut's target, which is essential for understanding what the shortcut would execute.

Exam trap

The trap here is assuming that jumplists or recent documents registry keys contain the same level of detail as the .lnk file itself, when they often only provide a reference to the file.

156
MCQmedium

Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?

A.pstree
B.cmdline
C.netscan
D.dlllist
AnswerB

The cmdline plugin specifically retrieves the command-line arguments from the process's PEB (Process Environment Block). This provides the full string used to start the process, which often includes malicious paths, obfuscated arguments, or external command-and-control parameters that are vital for forensic analysis of the execution.

Why this answer

The 'cmdline' plugin in Volatility 2 or the equivalent 'windows.cmdline' in Volatility 3 is essential for surfacing the exact arguments used to launch a process. Attackers frequently use command-line arguments to pass encoded payloads, configure malicious scripts, or perform lateral movement tasks. Identifying these arguments provides the context necessary to understand the intent of the process, which is often hidden when looking only at the process name or binary path.

Exam trap

Candidates often select generic process listing plugins like 'pslist' which only show process names, forgetting that specific argument flags require dedicated command-line extraction plugins.

157
MCQhard

During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?

A.The file content is likely recoverable, but you must check the $Bitmap metadata file to confirm the clusters are not reallocated.
B.The file content is unrecoverable because the MFT entry is unallocated, which means the data runs are invalid.
C.The file content can be fully recovered because the data runs are intact and point to clusters that have not been overwritten.
D.The file content can be recovered only if the $LogFile contains a record of the file's deletion.
AnswerA

The $Bitmap file tracks cluster allocation. Even if the MFT entry is unallocated, the clusters may still be free. Checking $Bitmap confirms whether the data runs point to allocated clusters. If the clusters are free, recovery is likely; if allocated, the content may be partially or fully overwritten.

Why this answer

When an MFT entry is unallocated, the file's data runs may still be present, but the clusters they point to could have been reallocated. The $Bitmap metadata file tracks which clusters are in use. To determine recoverability, the analyst must check whether the clusters are marked as free in $Bitmap.

If free, the content can likely be recovered; if allocated, the content may be overwritten.

Exam trap

The trap here is equating an unallocated MFT entry with unrecoverable data, overlooking that cluster allocation status is the decisive factor for content recovery.

158
Multi-Selectmedium

An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)

Select 2 answers
A.Application event log (Event ID 1000)
B.SAM registry hive
C.Security event log (Event ID 4720 and 4624)
D.System event log (Event ID 7045)
E.Prefetch files
AnswersB, C

The SAM registry hive stores local user account information, including usernames, password hashes, and account creation dates. Analyzing the SAM hive can reveal the presence of the newly created local account, even if event logs have been cleared. It provides a persistent record of the account's existence and attributes.

Why this answer

The Security event log records account creation (4720) and logon events (4624), providing a timeline of the attacker's actions. The SAM registry hive stores the local account database, including the new account's details, and can be analyzed even if logs are cleared. Together, they offer direct evidence of the new account and its use, which is critical for understanding the persistence mechanism.

Exam trap

The trap here is assuming that any log mentioning account activity is sufficient, while overlooking that the SAM hive provides persistent account data even if event logs are cleared.

159
MCQhard

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

A.The process is running as NT AUTHORITY\SYSTEM.
B.The parent process is services.exe.
C.The process is establishing an outbound connection to an external IP address.
D.The process is using a high-numbered ephemeral port.
AnswerC

Domain controllers should have strictly controlled outbound traffic profiles. An established connection to an arbitrary external IP address from a core infrastructure process like svchost is a classic indicator of compromise, suggesting the system is acting as a pivot or is participating in a command-and-control communication channel.

Why this answer

While svchost.exe is a legitimate Windows service host, the network connection originating from a domain controller to an external IP address is highly suspicious. Legitimate domain controller service traffic should be directed towards internal domain members or approved update servers. This specific pattern, combined with the process context, indicates potential lateral movement or data exfiltration attempts using a masqueraded system process to bypass basic security controls.

Exam trap

Examinees often assume processes named svchost.exe are automatically safe even when running on a domain controller with anomalous network destinations.

160
Multi-Selecthard

When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?

Select 3 answers
A.Memory segments marked as PAGE_EXECUTE_READWRITE
B.The presence of standard DLLs in the loading list
C.Memory regions that are executable but not file-backed
D.The thread environment block (TEB) memory region
E.Discrepancy between disk and memory on-disk binaries
AnswersA, C, E

Memory pages with Read, Write, and Execute (RWX) permissions are rare in legitimate software. These permissions are often a requirement for self-modifying code or injected payloads, making them a primary target for finding malicious code that needs to both write its payload and subsequently execute it.

Why this answer

Code injection often involves modifying existing memory segments or creating new ones with abnormal permissions. Analysts must look for areas of memory that are marked as executable but do not map to a file on disk (private memory), detect hooks in common system libraries, or identify discrepancies between memory-resident code and the original binary on disk. These indicators are classic signs that a process has been tampered with to execute malicious logic.

Exam trap

Candidates often focus only on the MZ header, ignoring that modern fileless malware can hide by hooking system calls or modifying existing legitimate memory regions without necessarily needing a new PE header.

161
MCQeasy

An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?

A.$Index allocation attributes within directory entries
B.$Bitmap
C.$MFT
D.$Root
AnswerA

NTFS directories store index entries in $INDEX_ROOT and $INDEX_ALLOCATION attributes. These entries map file names to their MFT record numbers. By traversing the directory hierarchy, an examiner can resolve the full path to the file's MFT record number. This is the correct method for path-to-record resolution.

Why this answer

To map a file path to its MFT record number, an examiner must traverse the directory index structures. Directories in NTFS use $INDEX_ROOT and $INDEX_ALLOCATION attributes to store entries that associate file names with MFT record numbers. Starting from the root directory and following each path component leads to the target file's record.

Exam trap

The trap here is assuming that $MFT or $Bitmap can directly resolve a file path, when only directory index attributes contain the name-to-record mapping.

162
MCQhard

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

A.The PID 1240 is assigned to svchost.exe
B.The existence of two svchost.exe processes
C.The parent-child relationship of svchost.exe and explorer.exe
D.The PID of explorer.exe is higher than svchost.exe
AnswerC

Explorer.exe is typically launched by userinit.exe during the login sequence. When svchost.exe, a process intended for background system services, spawns the shell, it indicates that the system has been compromised. This violation of established process lineage is a primary indicator of process injection or hollowing.

Why this answer

The exhibit shows explorer.exe being spawned by svchost.exe. In a standard Windows environment, explorer.exe is spawned by userinit.exe, which in turn is spawned by winlogon.exe. A service host process (svchost.exe) spawning the Windows shell is highly anomalous behavior.

This pattern suggests an injection or a process replacement attack where a malicious service has hijacked the shell or launched a secondary GUI interface for persistent command and control.

Exam trap

Candidates often misidentify legitimate svchost.exe behavior by assuming any child process of svchost.exe is malicious, failing to recognize that specific services like taskhostw.exe are legitimate children of svchost.exe.

163
MCQmedium

During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?

A.The file is fragmented across multiple clusters.
B.The file data is stored directly in the MFT record.
C.The file is encrypted with EFS.
D.The file is hidden from standard Windows APIs.
AnswerB

Resident data is stored within the MFT record itself, avoiding the need for cluster allocation. This is an optimization for small files (typically under 700-900 bytes). For forensic analysts, this means the file content is immediately available once the MFT record is parsed, without needing cluster map traversal.

Why this answer

A resident $DATA attribute means the file content is stored directly within the MFT record rather than in external clusters. This is common for very small files. Because the data is already inside the MFT record, you do not need to parse data runs or follow cluster pointers to extract the file, significantly simplifying the recovery process for small configuration or text files.

Exam trap

Students frequently mistake resident attributes for compressed files or think they require external data runs and cluster mapping to extract the content.

164
MCQmedium

An investigator is analyzing a Linux ext4 file system and needs to determine when a file's content was last modified. The file's inode contains ctime, mtime, and atime fields. Which timestamp should the investigator use to answer this specific question?

A.ctime
B.crtime
C.mtime
D.atime
AnswerC

mtime records the last time the file's content was modified. In ext4, any write to the file data updates mtime, making it the correct timestamp for determining when the content last changed. This directly answers the investigator's question about content modification time, assuming no timestamp manipulation has occurred.

Why this answer

In ext4, the mtime (modification time) field in the inode is updated whenever the file's content changes. It is the appropriate timestamp for determining when the file's data was last written. Other timestamps like ctime and atime serve different purposes and do not reflect content modification.

Exam trap

The trap here is confusing ctime with content modification time, when ctime actually tracks inode metadata changes.

165
MCQmedium

An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?

A.File Creation Timestamp
B.File Attribute Flags (MFT)
C.Extended Attributes (EA)
D.Access Control List (ACL)
AnswerB

The MFT stores the attributes for every file on an NTFS volume. The 'Hidden' attribute flag, when set, instructs the operating system to omit the file from standard folder views. Identifying this flag is essential for uncovering files that the attacker intentionally obscured from the user.

Why this answer

NTFS file attributes allow users to hide files from the standard Windows Explorer interface. By checking the File Attributes field in the Master File Table (MFT), an analyst can identify files marked with the 'Hidden' or 'System' attribute. This is a common, albeit simple, anti-forensics technique used by adversaries to prevent casual discovery of malicious binaries or staged data, and it is the first step in identifying deliberate concealment attempts.

Exam trap

Candidates often try to find the hidden file by searching for specific Registry keys, forgetting that the 'Hidden' attribute is a file-level metadata property stored within the MFT.

166
MCQhard

An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?

A.The process object was unlinked from the active process list to hide it from standard enumeration.
B.The process was terminated before the memory image was captured, so only residual pool data remains.
C.The pool scan plugin produced a false positive by matching a freed process object that has not yet been reused.
D.The process is a legitimate system process that is intentionally excluded from the active process list by the kernel.
AnswerA

A process that is missing from the active process list but still discoverable by a pool scan indicates that its list entry was removed, a technique known as DKOM. This is a hallmark of rootkit activity, because legitimate processes are not unlinked from the active list while they are running, and the pool scan finds the object because the structure itself remains allocated.

Why this answer

When a process is missing from the active process list but its object is still discoverable by scanning pool memory, the most likely explanation is that the list entry was removed to conceal the process. This is the classic signature of DKOM-based rootkit hiding, because the object remains allocated and its pointers are intact even though it is no longer linked into the list.

Exam trap

The trap here is concluding that a process found only by a pool scan must be a false positive or a terminated process, when the pattern is actually the expected signature of deliberate unlinking from the active process list.

167
MCQmedium

Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?

A.Using a Domain Admin account for all investigation tasks to avoid access issues.
B.Granting forensic responders full system access to all network segments.
C.Limiting IR account access to only the specific data and systems needed for the investigation.
D.Ensuring all IR accounts have a shared password for rapid response coordination.
AnswerC

By limiting the permissions of an IR account to exactly what is needed—such as log reading or forensic disk access—the organization mitigates the risk of credential theft. This practice ensures that even if an account is compromised, the attacker is limited in their ability to escalate or expand their foothold.

Why this answer

Using dedicated, limited-scope accounts for incident response ensures that if the responder's account is compromised, the attacker does not gain enterprise-wide administrative access. By providing only the permissions necessary for the investigation—such as read-only access to logs or forensic imaging permissions—the risk of accidental or malicious damage to the production environment is minimized, ensuring that the integrity of the IR process remains intact even in a hostile or complex environment.

Exam trap

Candidates often interpret 'Least Privilege' as 'using a regular user account'. In an IR context, it means providing the absolute minimum access required for the specific forensic task, not just 'low' access.

168
MCQhard

An enterprise incident responder is analyzing a compromised Linux server. The attacker used a rootkit that hooks system calls to hide processes and files. Which forensic technique is most effective to detect the rootkit's presence and identify hidden processes?

A.Run chkrootkit and rkhunter to scan for known rootkit signatures.
B.Inspect the output of netstat -tulpn for unusual listening ports.
C.Use Volatility to analyze a memory dump for hidden processes.
D.Compare the output of ps and /proc directory listings.
AnswerD

A system call hooking rootkit often manipulates the output of tools like ps by intercepting system calls. However, the /proc file system is maintained by the kernel and may still contain entries for hidden processes. Comparing ps output with the contents of /proc can reveal discrepancies where processes exist in /proc but are not shown by ps, indicating rootkit activity.

Why this answer

A system call hooking rootkit often intercepts system calls used by tools like ps, causing them to omit hidden processes. The /proc file system, however, is generated by the kernel and may still list all processes. By comparing the process list from ps with the directory entries in /proc, an investigator can identify processes that are present in /proc but missing from ps, indicating rootkit manipulation.

This technique is a classic method for detecting user-mode rootkits.

Exam trap

The trap here is relying solely on signature-based rootkit scanners, which may fail against custom rootkits, instead of using a direct comparison method that exposes kernel-level discrepancies.

169
MCQeasy

An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?

A.The $LogFile contains records of file system transactions, and it retains entries for files that were deleted, which the tool interprets as current files.
B.The $UsnJrnl records all changes to files, including deletions, and it retains the file names and timestamps for deleted files indefinitely.
C.The $MFT contains entries for deleted files that have not been overwritten, and these entries represent files that once existed and may still be recoverable.
D.The $Bitmap tracks cluster allocation, and it includes entries for files that were deleted but whose clusters have not been reallocated.
AnswerC

This is correct because the $MFT retains entries for deleted files until they are overwritten. When a file is deleted, its MFT record is marked as unallocated, but the record content, including timestamps and file name, often remains intact. The Sleuth Kit's fls tool can parse these unallocated entries and include them in the bodyfile, resulting in timeline entries for files that no longer exist. These entries are valuable because they indicate past file presence and can be used to reconstruct historical activity, and the data may still be recoverable if the clusters have not been reused.

Why this answer

The correct answer is the option describing the $MFT. NTFS keeps MFT records for deleted files in an unallocated state until they are reused. The Sleuth Kit's fls tool reads these records and includes them in the bodyfile, causing deleted files to appear in the timeline.

Investigators should interpret such entries as evidence of past file existence and potential recoverable data. The $MFT is a primary source for file system timeline reconstruction, especially for files that have been deleted but not overwritten.

Exam trap

The trap here is assuming that deleted files cannot appear in a timeline generated by fls, when in fact unallocated MFT entries are parsed and can produce such entries.

170
MCQeasy

A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?

A.Compute a cryptographic hash of the memory image immediately after acquisition and record it in the case notes.
B.Compress the memory image with a proprietary format to reduce its size before hashing.
C.Open the memory image in a hex editor to verify its contents before storing it.
D.Store the memory image on the same server from which it was captured to preserve chain of custody.
AnswerA

Hashing the image right after acquisition creates a verifiable baseline for integrity. Any later comparison can confirm the image is unchanged. This is a fundamental forensic practice that supports admissibility and defensibility, and it applies directly to memory images just as it does to disk images, ensuring the evidence can be trusted throughout the investigation.

Why this answer

Cryptographic hashing immediately after acquisition establishes a verifiable integrity baseline for the memory image. Storing the image on the source host, using proprietary compression before hashing, or inspecting it in a hex editor does not provide that assurance and may introduce risk. Hashing is the standard, defensible method to demonstrate the image has not been altered.

Exam trap

The trap here is equating any handling step with integrity preservation, when only cryptographic hashing provides a verifiable baseline.

171
MCQmedium

Which of the following is true regarding the 'MFT Change' timestamp?

A.It is updated whenever the file's content changes.
B.It tracks when the file metadata was last modified.
C.It is easily modified by standard user applications.
D.It is identical to the file's creation time.
AnswerB

The MFT Change timestamp reflects the last time the file's MFT record metadata was modified. This includes operations like renaming, changing permissions, or moving the file. It is a distinct temporal artifact from the file content modification time and provides critical context for structural changes to the file system.

Why this answer

The 'MFT Change' (or 'Entry Modified') timestamp is updated whenever the metadata of the file record itself is changed, such as by moving the file, renaming it, or changing its permissions. Unlike the 'Modified' timestamp, which tracks file content changes, the MFT change timestamp is exclusively tied to the record metadata. This makes it a unique indicator for tracking structural changes to a file that may be missed if looking only at content modification times.

Exam trap

Candidates frequently confuse the MFT Change timestamp with the standard file modification time, assuming it tracks content changes rather than structural metadata changes to the MFT record.

172
MCQhard

You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?

A.A legitimate administrator mistyped the password several times and then correctly added a new support user.
B.The deploy account was used by an automated deployment tool that periodically re-authenticates and updates sudoers.
C.The server experienced a PAM misconfiguration that logged failed attempts while still allowing the successful login.
D.A brute-force password attack succeeded against the deploy account, and the attacker then escalated privileges via sudo.
AnswerD

The repeated failures followed by a success from the same source IP describe a successful brute-force or password-guessing attack. The subsequent sudo invocation that adds a user to sudoers is a classic privilege escalation and persistence step, since it creates a second account with administrative rights. Both events, tied to the same session, form a coherent intrusion chain.

Why this answer

The sequence of many failed password attempts ending in one success from the same IP shows a successful credential-guessing attack. The immediate sudo action that adds a new sudoer account indicates the attacker established persistence and elevated access. Investigators should trace the source IP, review command history and auth logs for the session, and check for additional accounts or scheduled jobs created by the attacker.

Exam trap

The trap here is treating a single successful login as benign without correlating it to the preceding failure burst and the privileged change that follows.

173
MCQeasy

A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?

A.windows.svcscan
B.windows.modules
C.windows.dlllist
D.windows.driverscan
AnswerB

The windows.modules plugin parses the kernel's module list (PsLoadedModuleList) and outputs each loaded driver, including its base address, size, and full path. This directly satisfies the requirement to enumerate kernel modules from a memory image and compare against the OS-reported list for discrepancies.

Why this answer

The windows.modules plugin is designed to walk the kernel's loaded module list (PsLoadedModuleList) and display each module's name, base address, size, and path. This directly supports the analyst's goal of enumerating kernel modules from a memory image and comparing them against the operating system's reported list to identify discrepancies.

Exam trap

The trap here is confusing kernel module enumeration with driver object scanning or user-mode DLL listing, which serve different forensic purposes.

174
MCQmedium

An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?

A.The memory acquisition tool utilized an unprivileged user-mode API that restricted kernel visibility.
B.The malware executed direct kernel object manipulation to remove the process entries from the active process doubly-linked list.
C.The operating system automatically paged the missing process control blocks out to the swap file during memory dumping.
D.Volatility 3 requires an outdated symbol table to correctly resolve the exact offsets of the Windows 10 kernel structures.
AnswerB

DKOM lets malware unlink an EPROCESS entry from the active process doubly-linked list, so Volatility 3's list-walk traversal cannot reach it. The processes remain resident in memory, which is why the stem's aggressive kernel driver acquisition still captured them but standard enumeration missed them.

Why this answer

Standard process enumeration in Volatility relies on traversing the ActiveProcessLinks doubly-linked list rooted in the PsActiveProcessHead pointer. Advanced malware frequently unlinks EPROCESS structures from this list via direct kernel object manipulation to evade standard task manager visibility. Analysts must utilize kernel pool scanning plugins like pslist alternatives to recover these hidden entries.

Exam trap

Students often assume standard process listing plugins will uncover all running programs, forgetting that sophisticated rootkits routinely unlink EPROCESS structures from active lists.

175
Multi-Selecthard

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Select 3 answers
A.Memory Page Permissions (RWX)
B.The system's Event Log files
C.Unbacked executable memory
D.The MFT file records
E.Discrepancies in the Process VAD tree
AnswersA, C, E

Executable memory regions that are marked as Read-Write-Execute (RWX) are highly suspicious. Legitimate processes rarely require memory to be writable and executable simultaneously. Attackers often use these permissions to write shellcode to a buffer and then execute it, making this a primary indicator of process injection.

Why this answer

Process injection techniques often modify memory protections or inject code into existing legitimate processes. By comparing the disk-based image of a process with its memory-based representation, analysts can identify discrepancies in executable sections. Checking memory protections (e.g., RWX permissions) and identifying unbacked executable code in private memory regions are the primary methods for uncovering sophisticated persistent threats that operate entirely within the volatile memory space.

Exam trap

Candidates often focus on file hashes or process names, which are easily spoofed, rather than inspecting memory-specific indicators like VAD tree anomalies or RWX memory regions.

176
Multi-Selecthard

Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?

Select 2 answers
A.Updating system drivers
B.Timestomping
C.Log clearing
D.Using a web browser
E.Renaming a file
AnswersB, C

Timestomping is the intentional modification of file metadata to mislead investigators. By altering the SI attributes, an attacker hides the true age of a malicious file, making it appear as a legitimate system file or part of a different time window, which is a direct attack on forensic timeline integrity.

Why this answer

Attackers utilize anti-forensic techniques to break the chain of evidence. Timestomping specifically invalidates the reliability of file metadata, while log clearing removes the context required for correlation. Both techniques force analysts to move deeper into secondary artifacts like the USN Journal or volume shadow copies, significantly increasing the time and complexity of an investigation while testing the analyst's ability to cross-reference multiple data sources for evidence.

Exam trap

Candidates often confuse general system maintenance tasks with anti-forensic techniques, failing to identify that log clearing and timestomping are specifically intended to obstruct the reconstruction of a timeline.

177
MCQhard

An investigator is analyzing MACB timelines on a Windows system and needs to differentiate between a file being copied versus being moved within the same NTFS volume. Which timeline artifact behavior distinguishes an intra-volume file move from a file copy operation?

A.An intra-volume move operation creates a brand-new $MFT record with current creation timestamps, while a copy preserves the original record.
B.An intra-volume move updates the parent directory index while preserving the original $MFT record's creation timestamp, whereas a copy generates a new $MFT record with a new creation time.
C.Both operations generate identical $MFT records because NTFS abstracts file movement as a symbolic link creation process.
D.A file copy updates the $STANDARD_INFORMATION attribute while leaving $FILE_NAME untouched, whereas a move updates both simultaneously.
AnswerB

Moving a file within the same NTFS volume reuses the existing MFT record, updating only the parent directory references and ctime. Conversely, copying allocates a completely new MFT record, assigning a fresh creation timestamp to the destination file.

Why this answer

Differentiating file movement from copying is essential for tracking data exfiltration and staging on a compromised system. Within the same NTFS volume, a move operation retains the original $MFT record and updates directory pointers, whereas copying creates an entirely new $MFT record with fresh creation timestamps, providing a clear footprint in timeline analysis.

Exam trap

Candidates often assume that moving a file generates a new MFT record, failing to distinguish between the pointer updates of a move and the creation of a new entry during copy.

178
MCQmedium

An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?

A.The file was compressed using NTFS compression, which automatically updates the $STANDARD_INFORMATION modification timestamp while leaving $FILE_NAME untouched.
B.An automated defragmentation utility ran on the volume, updating the high-level metadata without altering the underlying filename structure.
C.The file was likely subjected to time-stomping where user-space tools altered the $STANDARD_INFORMATION attributes, leaving the original $FILE_NAME timestamps intact.
D.The operating system experienced an unclean shutdown, causing the lazy writer thread to flush $STANDARD_INFORMATION changes out of synchronization with $FILE_NAME.
AnswerC

User-space anti-forensic tools typically modify only the easily accessible $STANDARD_INFORMATION attribute. Because the NTFS kernel driver maintains the $FILE_NAME attribute during standard renaming and creation actions, the older $FILE_NAME timestamp frequently survives, exposing the tampering attempt to investigators.

Why this answer

Timestamp discrepancies between the $STANDARD_INFORMATION and $FILE_NAME attributes often indicate file manipulation, copying, or time-stomping. Since the $STANDARD_INFORMATION attribute can be easily modified by user-space APIs while the $FILE_NAME attribute is managed directly by the NTFS driver, comparing both provides crucial insight into anti-forensic activities and accurate timeline reconstruction during incident response investigations.

Exam trap

Candidates often incorrectly assume that the $STANDARD_INFORMATION attribute is the 'truth' when discrepancies exist, ignoring the kernel-level reliability of the $FILE_NAME attribute in detecting timestomping.

179
MCQmedium

During an enterprise incident response, you need to collect volatile evidence from a compromised Windows server that is still powered on. The server is business-critical and cannot be taken offline. Which of the following is the most appropriate order for collecting volatile data, according to RFC 3227 guidelines?

A.Collect network connections, then disk, then memory, then running processes.
B.Collect the disk image first to preserve the most evidence, then memory, then network connections.
C.Collect the contents of physical memory, then network connections, then running processes, then disk.
D.Collect running processes, then disk, then memory, then network connections.
AnswerC

RFC 3227 specifies order of volatility: memory and network state are more volatile than process table and disk. Collecting memory first preserves the most perishable evidence. Network connections and running processes change rapidly, but memory is lost entirely upon shutdown, so it must be captured before other artifacts. Disk is least volatile and can be collected later.

Why this answer

The order of volatility dictates that the most perishable evidence be collected first. Physical memory and network connections are extremely volatile; running processes are less so but still change; disk is least volatile. Therefore, memory should be captured first, followed by network connections, then processes, and finally disk.

This minimizes loss of evidence.

Exam trap

The trap here is assuming that disk imaging should be prioritized because it captures the most data, but volatile evidence like memory and network state can be lost forever if not collected first.

180
MCQhard

You are examining a Windows Server 2019 memory image after a suspected credential-theft incident. You need to identify which process was used to access the LSASS process memory at the time of capture. Which Volatility 3 plugin and artifact combination most directly reveals handles opened to the LSASS process by other processes?

A.windows.netscan, filtering for connections owned by lsass.exe
B.windows.dlllist, focusing on unsigned DLLs loaded into lsass.exe
C.windows.malfind, looking for PAGE_EXECUTE_READWRITE regions in lsass.exe
D.windows.handles, filtering for handles to the lsass.exe process object
AnswerD

windows.handles enumerates the handle table of each process and shows the object type and object name. Filtering for lsass.exe reveals which processes held handles to the LSASS process object, providing direct evidence of access at capture time. This is the most targeted way to identify a process that opened LSASS for memory access.

Why this answer

Handle tables record which process opened an object and what type it is. Filtering the handle output for the lsass.exe process object pinpoints processes that held a handle to LSASS at capture time, which is strong evidence of memory access. Injected-memory, network, and loaded-module plugins examine other artifacts and do not answer who opened the handle.

Exam trap

The trap here is conflating injected memory inside LSASS with a handle opened to LSASS; malfind finds the former, while the handle table shows the latter.

181
MCQmedium

During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?

A.The file system metadata was actively corrupted by malware to hinder timeline analysis.
B.The file was copied from another location, preserving the original modified timestamp while generating a new creation timestamp.
C.The operating system experienced a severe clock synchronization failure during the write operation.
D.An automated defragmentation utility reorganized the cluster chain and inadvertently swapped the metadata values.
AnswerB

Copying a file to a new NTFS destination assigns a fresh creation timestamp representing the exact moment of creation on the target volume. However, the modified timestamp is often preserved from the source file, creating an apparent chronological inversion that immediately flags the file as a copy.

Why this answer

An $MFT record reflecting a modified time earlier than the creation time frequently occurs when a file is copied rather than moved. The copy operation assigns a new creation timestamp to the destination file while preserving the original modified timestamp from the source file. Recognizing this artifact helps forensic analysts trace the origin of stolen payloads across network shares or external drives.

Exam trap

Candidates often assume this is a sign of timestomping or system clock manipulation. They overlook the standard behavior of file systems when copying files across volumes.

182
MCQmedium

An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?

A.windows.modules
B.windows.driverscan
C.windows.psscan
D.windows.svcscan
AnswerA

windows.modules parses the kernel's PsLoadedModuleList to enumerate loaded kernel drivers and modules, reporting their names, base addresses, and sizes. This directly supports building a baseline comparison for rootkit detection. The plugin works on Windows memory images and is the standard Volatility 3 replacement for the legacy Volatility 2 modlist plugin.

Why this answer

windows.modules enumerates loaded kernel modules by traversing PsLoadedModuleList, yielding names, base addresses, and sizes suitable for baseline comparison. The other plugins target different artifacts: driverscan finds driver objects via pool scanning, svcscan lists services, and psscan recovers process objects. Only windows.modules directly satisfies the stated requirement on a Windows memory image.

Exam trap

The trap here is confusing module listing with driver scanning, since both relate to kernel code but produce different evidence sets.

183
MCQeasy

A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?

A.windows.cmdline
B.windows.psscan
C.windows.pslist
D.windows.pstree
AnswerB

windows.psscan scans physical memory for process objects, including those that have been terminated but not yet overwritten. It can find residual process structures that are no longer in the active process list. This makes it the correct plugin to identify terminated processes that may still have forensic artifacts in memory.

Why this answer

The windows.psscan plugin scans physical memory for process objects, which allows it to find processes that have been terminated but whose structures have not been overwritten. This is useful for identifying residual evidence from terminated processes. In contrast, pslist and pstree only show active processes, and cmdline provides arguments for active processes.

Therefore, psscan is the correct choice for finding terminated processes in a memory dump.

Exam trap

The trap here is assuming that terminated processes are completely removed from memory, but their structures can linger until overwritten, which psscan can detect.

184
MCQhard

An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?

A.Memory dumps of the injected process
B.Windows Event Logs (Security.evtx)
C.Shimcache
D.Prefetch files
AnswerA

Memory dumps of the injected process can reveal the presence of the malicious DLL in the process's address space. Tools like Volatility's malfind or dlllist can detect injected code by looking for memory regions with unusual permissions or unlinked DLLs. This is the most direct evidence of DLL injection.

Why this answer

DLL injection leaves artifacts in the memory of the target process. Analyzing a memory dump with forensic tools can reveal injected DLLs, often by identifying memory regions with executable permissions that are not backed by a file on disk, or by finding DLLs not listed in the process's module list. This provides direct evidence of the technique.

Exam trap

The trap here is assuming that execution artifacts like Prefetch or Shimcache would show the malicious DLL, but they only track executable files, not injected code within another process.

185
MCQmedium

Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?

A.pslist
B.malfind
C.handles
D.dlllist
AnswerB

The malfind plugin identifies memory regions that are both executable and private (not mapped to a file on disk). This is a strong indicator of injected code, as most legitimate executables are backed by files. It is the go-to tool for finding shellcode and non-persistent malicious code running in memory.

Why this answer

The 'malfind' plugin scans memory for regions that are marked as executable (X) but are not backed by a file on disk (VAD tags). This is the standard method for finding shellcode or injected DLLs, which are common in fileless malware. It matters because attackers often use memory injection to bypass signature-based antivirus, and detecting these unbacked regions is the primary way to uncover such hidden malicious execution.

Exam trap

Candidates often choose general process listing plugins like pslist, which do not inspect memory permissions or identify unbacked executable regions effectively.

186
MCQmedium

Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?

A.System event logs for service failures.
B.Security event logs for Event ID 4624.
C.Application event logs for crash dumps.
D.DNS query logs from the domain controller.
AnswerB

Event ID 4624 captures successful logons. During a Pass-the-Hash attack, the analyst looks for anomalous authentication patterns, such as the use of NTLM for logons that should be Kerberos, or logins occurring from systems that do not usually communicate with the target, indicating the reuse of intercepted hashes.

Why this answer

Pass-the-Hash attacks involve an attacker using an NTLM hash to authenticate as a user without the cleartext password. This typically manifests in the Security event log during the authentication process. By looking for specific logon types and unusual source-to-destination authentication flows, analysts can detect when a hash has been reused across the network, even if the attacker never obtained the actual password through brute force or phishing.

Exam trap

Candidates mistakenly focus on generic login failures (4625) rather than successful logins (4624). Pass-the-Hash relies on valid authentication using a captured hash, so it appears as a successful logon event.

187
MCQeasy

A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?

A.The file has multiple $DATA attributes, indicating alternate data streams.
B.The file is compressed, and the $ATTRIBUTE_LIST contains the compression unit size.
C.The file's attributes are spread across multiple MFT records because they do not fit in a single record.
D.The file is encrypted with EFS, and the $ATTRIBUTE_LIST stores encryption keys.
AnswerC

The $ATTRIBUTE_LIST attribute is used when a file's attributes exceed the space available in a single MFT record. It lists the attributes and their locations, which may be in additional MFT records. This allows NTFS to manage files with many attributes or large attributes that cannot be stored in one record. This is the primary purpose of the $ATTRIBUTE_LIST.

Why this answer

The $ATTRIBUTE_LIST attribute is present when a file's attributes cannot fit in a single MFT record. It enumerates the attributes and their locations, which may be in additional MFT records. This is common for files with many attributes or large attributes like long $DATA runs or numerous alternate data streams.

Its presence indicates that the file's metadata is distributed across multiple MFT records.

Exam trap

The trap here is confusing $ATTRIBUTE_LIST with attributes that indicate specific features like encryption or compression, when it is actually a structural mechanism for managing attribute overflow.

188
MCQmedium

Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?

A.The thread environment block (TEB)
B.The process security token
C.The process environment block (PEB)
D.The registry hive file for the user
AnswerB

The process security token is a kernel object that represents the user's security context. It contains the SIDs for the user and their groups, which directly indicate the account identity that owns the process, providing the necessary evidence for identifying which user account executed the malware.

Why this answer

In Windows, every process is associated with a security token object that defines the user's identity, privileges, and groups. By extracting the security token structure associated with an EPROCESS object in memory, an analyst can determine the exact user context under which the process is executing. This is vital for determining if a process was launched with system privileges or by a compromised local user account during an incident.

Exam trap

Candidates often look for the user's profile path or environmental variables, which can be spoofed, rather than the kernel-level security token which serves as the authoritative source for process identity.

189
MCQmedium

During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?

A.The SYSTEM registry hive, specifically the Services key under CurrentControlSet
B.The Windows Event Log Security.evtx for event ID 4697
C.The SOFTWARE registry hive, specifically the Microsoft\Windows\CurrentVersion\Run key
D.The NTFS $MFT to identify recently created executable files in System32
AnswerA

The SYSTEM registry hive contains the Services subkey under CurrentControlSet, which stores service configuration including the ImagePath, Start type, and ObjectName. This is the authoritative source for service persistence. Examining it directly reveals malicious services even if the Service Control Manager database is cleared or the service is set to disabled, making it the first artifact to check.

Why this answer

The SYSTEM registry hive stores all service configurations under CurrentControlSet\Services, including the binary path, start type, and account. This makes it the definitive artifact for identifying malicious service persistence. Other artifacts like the Run key, $MFT, or event logs may provide context but do not contain the full service configuration needed for triage.

Exam trap

The trap here is assuming that the Run key or event logs provide service configuration details, when only the SYSTEM hive's Services key contains the authoritative ImagePath and Start values.

190
MCQmedium

When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?

A.DNS cache
B.TCP Endpoint structures
C.Shimcache
D.Amcache.hve
AnswerB

TCP Endpoint structures in memory store the state of all active and listening network connections, including the associated process ID. By parsing these structures from a memory dump, an analyst can definitively link network traffic to a specific, potentially malicious process, regardless of whether the connection is hidden from standard OS tools.

Why this answer

The TCP Endpoint structures in kernel memory are essential for mapping network activity to process ownership. Attackers often attempt to hide connections using rootkit techniques, but these structures in memory usually remain accurate. Linking a specific PID to a remote IP address allows the analyst to identify Command and Control (C2) communication, which is the most reliable way to identify an active, compromised host during a live incident response.

Exam trap

Candidates often suggest checking netstat output or active connection logs, which can be hooked or hidden by rootkits, rather than inspecting the kernel-level TCP structures.

191
MCQhard

An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?

A.The task appears legitimate, but the analyst should verify the binary's digital signature and compare the creation timestamp against the Edge installation baseline.
B.The task is definitely a persistence mechanism because it runs at logon and uses the '/ua' switch, which is undocumented.
C.The task is malicious persistence because SYSTEM-created tasks in the Microsoft namespace are not legitimate.
D.The task is suspicious because the executable path uses the 'Program Files (x86)' directory on a 64-bit server.
AnswerA

All observed attributes — namespace, executable path, argument, owner, and timestamp — align with a standard Edge updater installation. Because scheduled tasks are a common persistence mechanism, best practice is to confirm the binary is signed by Microsoft and that the timestamp matches the known Edge install baseline. This combination of corroboration supports a benign classification while still applying forensic rigor.

Why this answer

Every attribute of the task — its folder, name, executable, argument, owner, and modification time — is consistent with the Edge updater installed on the server. Scheduled tasks are nonetheless a popular persistence vector, so the correct posture is to corroborate with signature verification and timestamp comparison against the known Edge installation baseline before clearing it.

Exam trap

The trap here is treating the presence of a SYSTEM-owned scheduled task in a Microsoft vendor namespace as inherently suspicious, when this is exactly how legitimate vendor updaters are deployed.

192
MCQhard

An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?

A.It records the deletion of a user account from the local database.
B.It logs that a system service was started by the Service Control Manager.
C.It signals the installation of a new service on the system.
D.It documents a failed attempt to modify an existing service.
AnswerC

Event 4697 tracks service installation. Attackers often install services to maintain persistence, ensuring their malware runs with high privileges after a reboot. Detecting this event allows the investigator to extract the service path and identify the malicious binary that was dropped and registered for automatic execution.

Why this answer

Event ID 4697 indicates that a new service was installed on the system. This is a common technique for attackers to establish persistence. By monitoring this event, analysts can identify when malicious binaries were registered as services to run automatically upon system boot.

This is critical for uncovering hidden persistence mechanisms and identifying the service name, binary path, and account used to execute the potentially malicious code.

Exam trap

Candidates frequently confuse Event ID 4697 with general service start events, failing to realize it specifically logs the installation of a new service, a common persistence indicator.

193
MCQhard

Refer to the exhibit. What is the most critical security concern presented by the second command line?

A.The usage of the 'echo' command.
B.The usage of 'IEX' to execute code in memory.
C.The creation of a text file in C:\Users\Public.
D.The command uses the 'hidden' window flag.
AnswerB

Invoke-Expression (IEX) allows PowerShell to execute strings as commands. Downloading a script from a URL and piping it to IEX is a common 'fileless' attack technique. This avoids writing the malicious script to disk, making it difficult for traditional file-based antivirus to detect or analyze the payload.

Why this answer

The command performs an 'In-Process' download and execution of a remote PowerShell script. By using 'IEX' (Invoke-Expression) combined with a web client download, the attacker executes the script directly in memory, bypassing the need to write a file to disk. This is a highly effective evasion technique that leaves minimal forensic footprint and is a standard delivery method for sophisticated, memory-resident malware payloads.

Exam trap

Candidates focus on the URL or the PowerShell process itself rather than the 'IEX' (Invoke-Expression) cmdlet. IEX is the specific mechanism that enables fileless, memory-resident execution of remote code.

194
Multi-Selecthard

A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)

Select 2 answers
A.A process with a large number of handles to named pipes
B.A process whose working set is larger than its private commit size
C.A memory region with PAGE_EXECUTE_READWRITE protection that is not backed by a file on disk
D.A DLL loaded from a path within the user's AppData directory
E.A thread whose start address falls outside any known module range in the process
AnswersC, E

Executable and writable memory that has no file backing is a classic indicator of injected code, because legitimate executables and DLLs are normally mapped from disk with read-only or execute-only protections. The combination of writability, executability, and no on-disk source strongly suggests an attacker allocated memory and wrote shellcode or a payload into it.

Why this answer

Process injection typically manifests as executable memory that is not backed by a file on disk and as threads whose start addresses fall outside any mapped module. These two findings together provide strong evidence that an attacker wrote and executed code within another process, whereas handle counts, working set ratios, and AppData DLL loads have legitimate explanations and are not specific to injection.

Exam trap

The trap here is treating any unusual process characteristic, such as a DLL loaded from AppData or a high handle count, as proof of injection, when injection specifically requires executable code in an unbacked region or a thread executing outside known modules.

195
MCQmedium

You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?

A.IDT (Interrupt Descriptor Table)
B.GDT (Global Descriptor Table)
C.SSDT (System Service Descriptor Table)
D.PTE (Page Table Entry)
AnswerC

The SSDT contains an array of function pointers that define the kernel services available to user applications. Malware frequently overwrites these pointers to redirect execution flow to malicious code, allowing for the subversion of system APIs without triggering traditional file-based detection mechanisms during memory forensics analysis.

Why this answer

The System Service Descriptor Table (SSDT) maps system calls to kernel-mode functions. Rootkits often modify these pointers to intercept process execution. By comparing the SSDT addresses against the kernel's base image, analysts can identify unauthorized redirections.

This is crucial for detecting stealthy malware that hides its presence by manipulating the standard system call flow, ensuring the integrity of core operating system operations.

Exam trap

Candidates often confuse the SSDT with the IDT or standard process environment blocks, misidentifying which table specifically handles system service dispatching.

196
Multi-Selecthard

A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)

Select 2 answers
A.$FILE_NAME timestamps
B.Volume Boot Record (VBR) timestamps
C.$Bitmap timestamps
D.Master File Table (MFT) record header timestamps
E.$STANDARD_INFORMATION timestamps
AnswersA, E

$FILE_NAME timestamps are updated by the file system during filename operations and are not directly modifiable by user-mode APIs. They often retain original values even when $STANDARD_INFORMATION is altered. Comparing these with $STANDARD_INFORMATION can expose timestomping. In this scenario, they are a key artifact for detecting inconsistencies.

Why this answer

Timestomping often modifies $STANDARD_INFORMATION timestamps while leaving $FILE_NAME timestamps unchanged. Comparing these two sets can reveal inconsistencies that indicate manipulation. Other artifacts like VBR, $Bitmap, or MFT record headers do not contain comparable per-file timestamps, so they are not useful for this specific detection.

Exam trap

The trap here is assuming that all NTFS metadata contains file timestamps, when only specific attributes like $STANDARD_INFORMATION and $FILE_NAME store them.

197
MCQhard

An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?

A.A hard link was created, so the original MFT record was repurposed while a new record was allocated for the additional filename reference.
B.The volume is part of a Distributed File System replica, and DFSR metadata duplicated the MFT record during replication.
C.The file was deleted and later a new file with the same name was created, leaving a stale MFT record alongside the active one.
D.The file was compressed, causing NTFS to create a shadow MFT record for the compressed data stream.
AnswerC

When a file is deleted, its MFT record is marked inactive but not immediately wiped; a new file with the same name receives a different record number. The stale record may retain a zero-length $DATA or residual attributes, while the new record holds the active data and an $OBJECT_ID assigned at creation, explaining the duplicate filename across two records.

Why this answer

NTFS does not immediately clear MFT records when files are deleted; the record is marked unallocated but its contents may persist until reused. A subsequent file with the same name is assigned a new record number, producing two records with the same $FILE_NAME. The active record typically contains the live $DATA and an $OBJECT_ID, while the stale record may show remnants such as zero-length data.

Exam trap

The trap here is assuming that a filename uniquely identifies an MFT record, when in fact NTFS can retain stale records for deleted files that share names with active files.

198
MCQhard

Refer to the exhibit. What can be inferred about the file activity?

A.The file was created and immediately deleted.
B.The file was created and then populated with data.
C.The file system is experiencing metadata corruption.
D.The timestamps reflect a timestomping attempt.
AnswerB

The 'File_Create' event followed by the 'Data_Extend' event demonstrates that the file was initialized on the file system and then subsequently received data. This sequential logging is characteristic of standard file write operations performed by applications or the operating system, providing a clear timeline of file usage.

Why this answer

The USN Journal logs multiple reasons for a single file entry. The 'File_Create' event followed by 'Data_Extend' indicates that a file was created and immediately populated with data. This is a common pattern for legitimate software installations or file writes.

Identifying this sequence helps investigators differentiate between simple file creation and the actual writing of content, which is key to confirming if a file was just an empty shell or a functional payload.

Exam trap

Candidates often misinterpret individual USN Journal entries in isolation, failing to recognize that the sequence of events (Create followed by Data_Extend) is required to confirm actual file population.

199
MCQeasy

An analyst is reviewing a Windows 10 system and wants to determine the last time the system was shut down. Which Windows event log and event ID should the analyst examine?

A.System log, event ID 6006
B.Security log, event ID 4647
C.Application log, event ID 1001
D.System log, event ID 6013
AnswerA

Event ID 6006 in the System log indicates that the event log service was stopped, which occurs during a clean shutdown. It is a reliable indicator of a graceful system shutdown. The timestamp of this event provides the time the shutdown process completed. This is the standard event used to determine shutdown time.

Why this answer

The System event log records event ID 6006 when the event log service is stopped during a clean shutdown. This event is a definitive indicator that the system was shut down gracefully. By examining the timestamp of event 6006, the analyst can determine the last shutdown time.

Other events like 6013 provide uptime but not shutdown time.

Exam trap

The trap here is confusing user logoff events or periodic uptime events with the actual system shutdown event, which is specifically recorded as event ID 6006 in the System log.

200
MCQeasy

An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?

A.The file's content is encrypted with EFS, and the resident $DATA attribute stores the encryption keys.
B.The file's content is stored entirely within the MFT record, and the analyst can recover it directly from the MFT without carving the disk.
C.The file's content is stored in clusters outside the MFT, and the analyst must use the data runs to locate it on disk.
D.The file's content is compressed and stored in the MFT record, requiring decompression before analysis.
AnswerB

A resident $DATA attribute means the file's content is small enough to fit within the MFT record, typically under approximately 700 bytes. The data is stored directly in the MFT entry, so the analyst can extract it by parsing the MFT record. This is a straightforward recovery because no cluster allocation or disk carving is required.

Why this answer

A resident $DATA attribute indicates that the file's content is small enough to be stored directly within the MFT record. This means the analyst can recover the file content by parsing the MFT entry, without needing to locate clusters on disk. It is a simpler recovery scenario than non-resident data, which requires following data runs to clusters.

Exam trap

The trap here is confusing resident $DATA with non-resident $DATA, or assuming that resident data implies compression or encryption when it simply means the data fits in the MFT record.

201
MCQeasy

A forensic analyst is creating a timeline from an NTFS volume and wants to include the $MFT's record number 0, which contains metadata about the MFT itself. What is the primary purpose of including this record in the timeline?

A.It contains the $MFT's own metadata timestamps, which can indicate when the MFT was last modified or extended, useful for detecting file system changes.
B.It stores the list of all deleted files, which can be used to recover evidence of file deletion.
C.It provides the creation timestamp of the volume, which is essential for establishing the system's install date.
D.It records the last time the volume was mounted, which is critical for correlating with external device connection times.
AnswerA

Record 0 is the $MFT's own file record. Its timestamps reflect changes to the MFT itself, such as when entries are added or removed, or when the MFT is extended. Including it in a timeline can help identify periods of significant file system activity or potential anti-forensic manipulation of the MFT.

Why this answer

MFT record 0 is the $MFT's own file record, and its timestamps track changes to the MFT structure itself. Including it in a timeline helps analysts identify when the MFT was modified, which can correlate with mass file operations or anti-forensic activity. It does not provide volume creation, deleted file lists, or mount times.

Exam trap

The trap here is confusing the $MFT's own record with the $Volume metadata file, which does contain volume creation information.

202
MCQhard

A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?

A.Windows Security event logs on the domain controller
B.Sysmon logs on user workstations
C.Firewall logs
D.Email gateway logs
AnswerD

Email gateway logs record all inbound and outbound email messages, including sender, recipient, subject, and attachment details. If the adversary used a phishing email with a malicious attachment, the gateway logs would show the delivery of that email, possibly with attachment names and hashes. This is the most direct evidence of the initial infection vector, allowing responders to trace the email back to the sender and identify other recipients.

Why this answer

Email gateway logs are specifically designed to record email metadata and content, including attachments. In a phishing incident, these logs provide the earliest evidence of the attack, showing the malicious email's delivery, sender, and attachment details. This allows responders to identify the initial vector, block similar emails, and notify other potential victims.

Other log sources may show subsequent activity but lack the email context.

Exam trap

The trap here is focusing on endpoint logs that show execution, while overlooking the email gateway logs that directly record the phishing email and its attachment.

203
MCQeasy

An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?

A.Indicates a successful system update; no action required.
B.Indicates a brute-force attack; lock the account and investigate.
C.Indicates a malware infection; format the hard drive.
D.Indicates a network failure; check the cabling.
AnswerB

A high volume of 4625 events signifies repeated failed authentication attempts, which is the textbook definition of a brute-force or password-spraying attack. Locking the account and investigating the source IP is the standard and necessary incident response procedure to mitigate the risk of credential compromise in this scenario.

Why this answer

Event ID 4625 indicates failed logon attempts. A high volume often suggests a brute-force or password-spraying attack. The immediate response should be to isolate the account and investigate the source of the failures to prevent unauthorized access.

This is a baseline security operation that every analyst must perform, as it is the most common indicator of credential-based attacks currently plaguing enterprise network environments.

Exam trap

Test-takers frequently mistake Event ID 4625 for successful logons or treat it purely as an informational alert, overlooking the critical need for immediate containment like account locking.

204
MCQmedium

What is the primary function of the ShellBags artifact in a Windows forensic investigation?

A.To track the history of web browser searches.
B.To log file deletion events in the Recycle Bin.
C.To demonstrate that a user navigated to a specific folder.
D.To record the last time a system was rebooted.
AnswerC

ShellBags registry keys are updated when a user opens a folder. Because these keys persist even after folders are deleted, they are excellent evidence for showing the user was present in a directory. This helps confirm user knowledge of specific files or directories during a forensic examination.

Why this answer

ShellBags are registry entries that store folder view preferences, such as window size, icon position, and folder sorting. For forensics, they are incredibly useful for proving that a user navigated to a specific directory in Windows Explorer. This is critical for demonstrating user intent, as it shows which folders were browsed, even if those folders were later deleted or were located on removable media that is no longer connected.

Exam trap

Candidates often assume ShellBags only track files that currently exist, failing to realize the artifact persists even after the target folders or external drives have been removed.

205
MCQmedium

When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?

A.Event ID 4688, because it tracks the exact time of user authentication.
B.Event ID 4624, because it captures the logon type and source workstation.
C.Event ID 4720, because it logs user account creation activity.
D.Event ID 4625, because it confirms the user has successfully bypassed MFA.
AnswerB

Event ID 4624 provides the critical context of how the user logged in, specifically via the Logon Type field. This allows investigators to differentiate between local interactive sessions and remote network sessions, which is essential for identifying unauthorized lateral movement across the domain during an incident investigation.

Why this answer

Event ID 4624 is the primary indicator of a successful logon. Analyzing Logon Type 2 (interactive) or Logon Type 10 (Remote Desktop) allows analysts to track user access patterns. Monitoring these events helps distinguish between routine administrative access and abnormal logins occurring at odd hours or from unusual source IPs, which are standard red flags for compromised credentials being used by threat actors to traverse the network.

Exam trap

Candidates often confuse Event ID 4624 with 4625 (failed login). 4624 is for successful logins, which is the only way to confirm an attacker has actually accessed the system.

206
MCQhard

During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?

A.The Security ID (SID) of the account in the 4624 event
B.The Logon Process and Authentication Package fields in the 4624 event
C.The Logon GUID field in the 4624 event
D.The Process ID and Process Name fields in the 4624 event
AnswerB

The Logon Process and Authentication Package fields distinguish a network logon initiated by a service (for example, NTLM or Kerberos via a service host) from an interactive or explicit credential use. A mismatch, such as an unexpected authentication package or logon process for that account, is a strong indicator of credential misuse for lateral movement rather than normal service behavior.

Why this answer

For a Logon Type 3 event, the Logon Process and Authentication Package fields reveal the mechanism used. A service account authenticating via its normal service process and package looks routine; the same account authenticating with an unexpected package or from an unusual logon process suggests credential theft and lateral movement. The other fields support correlation but do not distinguish method as directly.

Exam trap

The trap here is focusing on the account name or SID to judge legitimacy; the same account can be used legitimately or maliciously, so the authentication method fields are what differentiate the two.

207
MCQmedium

An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?

A.$FILE_NAME creation time
B.$LogFile transaction records
C.Volume Shadow Copy creation time
D.$STANDARD_INFORMATION creation time
AnswerA

The $FILE_NAME attribute in the MFT records a timestamp that is updated when a filename is created or changed on the volume. For a copied or renamed file, this timestamp can reflect the time the filename entry was established, which may differ from the $STANDARD_INFORMATION creation time. In this scenario, it is the appropriate artifact to check for the filename creation event around 14:00.

Why this answer

The $FILE_NAME attribute creation timestamp is updated when a filename is created or changed on an NTFS volume, making it a key artifact for detecting copy or rename activity. Unlike $STANDARD_INFORMATION, it is less commonly manipulated by user-mode APIs. In this case, it can reveal whether the filename appeared around 14:00, supporting or contradicting the user's statement.

Exam trap

The trap here is assuming the $STANDARD_INFORMATION creation time always reflects the original file creation, when it can be altered and may not capture filename changes.

208
MCQhard

A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?

A.Enable the 'Turn on PowerShell Script Block Logging' policy under Administrative Templates > Windows Components > Windows PowerShell.
B.Enable the 'Process Creation' audit policy under Local Policies > Audit Policy.
C.Enable the 'Include command line in process creation events' policy under Administrative Templates > System > Audit Process Creation.
D.Enable the 'Audit Process Creation' policy under Advanced Audit Policy Configuration > Detailed Tracking.
AnswerC

This policy, when enabled, configures Windows to include the full command line in Event ID 4688 process creation events. Without it, the command line field is blank. Enabling it ensures future events capture this critical detail for forensic analysis.

Why this answer

The 'Include command line in process creation events' policy is the specific setting that controls whether the command line is recorded in Event ID 4688. Enabling it ensures that future process creation events contain the full command line, which is essential for identifying malicious commands. Other audit policies enable the event but do not add command line data.

Exam trap

The trap here is assuming that enabling process creation auditing automatically includes command line data; in reality, a separate policy must be enabled to capture that detail.

209
MCQhard

During an investigation of a Windows system, an analyst is reviewing a supertimeline and observes that a suspicious executable's $STANDARD_INFORMATION timestamps are all set to a date years before the operating system was installed, while its $FILE_NAME timestamps reflect the actual installation period. The analyst suspects timestomping. Which conclusion is most defensible based on NTFS timestamp behavior?

A.The file's $MFT record sequence number was incremented, which reset the $STANDARD_INFORMATION timestamps to the volume creation date
B.The $FILE_NAME timestamps are unreliable because NTFS updates them only when the file is renamed
C.The discrepancy indicates the file was created by the operating system installer and later modified by a user
D.The $STANDARD_INFORMATION timestamps were likely altered by a tool that manipulates file times, since they precede the OS installation while $FILE_NAME reflects the true period
AnswerD

Timestomping tools commonly modify $STANDARD_INFORMATION timestamps because they are writable via user-mode APIs, while $FILE_NAME timestamps are harder to alter and often retain the true creation and modification periods. When $STANDARD_INFORMATION predates the OS installation and $FILE_NAME matches the actual activity window, the defensible conclusion is deliberate timestamp manipulation of $STANDARD_INFORMATION.

Why this answer

NTFS stores two independent timestamp sets: $STANDARD_INFORMATION, which is writable through common APIs and is the usual target of timestomping tools, and $FILE_NAME, which is updated only on filename-related operations and is harder to alter. A large backward shift in $STANDARD_INFORMATION that predates the OS installation, paired with $FILE_NAME timestamps matching real activity, is strong evidence of deliberate timestamp manipulation rather than normal system behavior.

Exam trap

The trap here is assuming the two NTFS timestamp sets always agree, when a selective backward shift in $STANDARD_INFORMATION is a classic timestomping indicator.

210
MCQmedium

An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?

A.A process named cmd.exe spawned a PowerShell process, which could indicate scripted or malicious activity.
B.The system automatically started a PowerShell process as part of a scheduled task.
C.PowerShell was used to execute a command that created cmd.exe.
D.A user manually opened a command prompt and then launched PowerShell.
AnswerA

Event ID 4688 records the creation of a new process and includes the creator process name. Here, cmd.exe is the creator of powershell.exe. This parent-child relationship is a common technique in malicious scripts, such as those used in fileless attacks or lateral movement. It does not prove maliciousness but is a suspicious pattern that warrants further investigation. This option accurately describes the event.

Why this answer

Event ID 4688 includes the creator process name and new process name. In this case, cmd.exe created powershell.exe, indicating a parent-child relationship that is often seen in malicious scripts, such as those that use PowerShell for download or execution. While it could be benign, it is a suspicious pattern that should be investigated further.

The other options either assume benign user action, introduce unsupported context, or reverse the relationship.

Exam trap

The trap here is assuming that any cmd.exe to powershell.exe chain is malicious, but it can be benign; however, the event itself only describes the relationship, not intent.

211
MCQmedium

An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to exfiltrate messages. The team has identified the compromised account and wants to determine the full scope of mailbox access and rule creation across the tenant. Which single action should the responder take to obtain the authoritative audit record of these activities?

A.Run a message trace in the Exchange admin center for the past 30 days
B.Inspect the Azure AD sign-in logs for the compromised account
C.Export the Unified Audit Log from the Microsoft 365 compliance center and filter for mailbox rule and access events
D.Review the mailbox owner's Outlook client logs on their workstation
AnswerC

The Unified Audit Log in the Microsoft 365 compliance center records mailbox access, rule creation, and other tenant activities across services. Exporting and filtering it for events such as New-InboxRule and MailItemsAccessed provides the authoritative, tenant-wide record needed to determine the full scope of the adversary's mailbox actions.

Why this answer

The Unified Audit Log is the authoritative tenant-wide record for mailbox access and rule creation in Microsoft 365. It captures events like New-InboxRule and MailItemsAccessed, allowing the responder to determine the full scope of adversary activity. Message trace, client logs, and Azure AD sign-in logs provide complementary but incomplete views and do not record the mailbox-level actions needed.

Exam trap

The trap here is assuming that message trace or Azure AD sign-in logs contain mailbox rule creation and access details, when those events are only recorded in the Unified Audit Log.

212
MCQhard

An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?

A.windows.driverirp
B.windows.devicetree
C.windows.ssdt
D.windows.callbacks
AnswerC

windows.ssdt parses the System Service Dispatch Table and compares each entry to the expected function based on the kernel module's export table, flagging entries that point outside the owning module. This directly detects SSDT hooks used by rootkits. It is the correct plugin for identifying hooked system service functions in this scenario.

Why this answer

The windows.ssdt plugin specifically parses the System Service Dispatch Table and compares each service routine pointer to the expected function address within the owning kernel module. Discrepancies indicate hooks, often used by rootkits to intercept system calls. The other plugins focus on callbacks, IRP handlers, or device trees, none of which directly analyze the SSDT for hooked entries.

Exam trap

The trap here is conflating different kernel hooking techniques, such as SSDT hooking versus IRP hooking or callback manipulation, and selecting a plugin that targets the wrong structure.

213
MCQmedium

An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?

A.Storing encrypted file passwords.
B.Providing a history of file system changes.
C.Maintaining the B-tree structure of directories.
D.Tracking user login and logout sessions.
AnswerB

The USN Journal logs every change made to files and directories on the volume. By parsing this file, investigators can reconstruct a timeline of events even if the original files were deleted. It is a critical artifact for understanding the sequence of events during a security incident.

Why this answer

The USN Journal ($UsnJrnl) provides a chronological log of all changes made to files and directories on an NTFS volume. For forensics, it is invaluable because it captures activity that may no longer be reflected in the current MFT, such as the creation and subsequent deletion of files, or directory renames, providing a persistent history of disk modifications for timeline reconstruction.

Exam trap

Many analysts mistakenly believe the USN Journal is a security log for user actions, failing to identify that it is a filesystem-level log of all changes to metadata.

214
Multi-Selecthard

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Select 2 answers
A.Windows Security event ID 4672 indicating special privileges assigned to a new logon for a service account.
B.Sysmon event ID 10 (ProcessAccess) where the target process is lsass.exe and the granted access includes 0x1010 or 0x1410.
C.Windows Security event ID 4688 with process creation for a known credential dumping tool, including its command line.
D.Presence of a memory dump file named lsass.dmp in a user-writable directory, with a corresponding Sysmon event ID 11 (FileCreate).
E.Windows Security event ID 4624 logon type 3 (network) from a workstation to the domain controller.
AnswersB, D

Sysmon event ID 10 logs process access events. When the target is lsass.exe and the granted access mask includes rights like PROCESS_VM_READ and PROCESS_QUERY_INFORMATION (commonly 0x1010 or 0x1410), it strongly indicates an attempt to read LSASS memory, which is a hallmark of credential dumping tools such as Mimikatz.

Why this answer

Sysmon ProcessAccess events targeting lsass.exe with access masks like 0x1010 or 0x1410 directly show attempts to read LSASS memory, which is central to credential dumping. Similarly, an lsass.dmp file created in a user-writable directory with a corresponding file creation event provides concrete evidence of memory dumping. Both artifacts are high-fidelity indicators of credential theft.

Exam trap

The trap here is focusing on process creation or logon events, which are indirect, instead of the direct memory access and dump file artifacts that prove LSASS was targeted.

215
Multi-Selectmedium

A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)

Select 2 answers
A.The in-use flag in the file's MFT record header, which indicates whether the record is allocated or unallocated.
B.The $Bitmap metadata file, which tracks the allocation status of clusters on the volume.
C.The $Secure metadata file, which contains security descriptors and can indicate whether the file was protected from deletion.
D.The $LogFile, which records all metadata transactions and can show the exact deletion operation.
E.The $UsnJrnl, which records file system changes including deletions and can provide a timestamp for the deletion event.
AnswersA, B

The MFT record header contains an in-use flag that NTFS sets to 0 when a file is deleted, marking the record as unallocated. This is a primary indicator that the file no longer exists in the active file system. The analyst can parse this flag directly from the MFT record to confirm the file's deletion state, independent of other metadata.

Why this answer

To confirm that a file's MFT record is unallocated and its clusters are free, the analyst should check the in-use flag in the MFT record header and the corresponding bits in the $Bitmap file. The in-use flag directly indicates whether the record is allocated, while the $Bitmap tracks cluster allocation across the volume. Together they provide definitive evidence of deletion and cluster reallocation status.

Exam trap

The trap here is assuming that the $UsnJrnl or $LogFile can confirm cluster reallocation, when only the $Bitmap tracks current cluster allocation status.

216
MCQmedium

A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?

A.Slack space within the INDX records in the $INDEX_ALLOCATION
B.The $REPARSE_POINT attribute in the directory's MFT record
C.The $LOGGED_UTILITY_STREAM attribute of the directory
D.The $BITMAP attribute of the directory's MFT record
AnswerA

INDX records in the $INDEX_ALLOCATION contain index entries and often retain stale or slack entries after a file is deleted. These residual entries can include the filename and file reference of a deleted file. Analyzing the slack space of these INDX records is a standard technique to recover evidence of deleted files from a directory index.

Why this answer

When a file is deleted from an NTFS directory, its entry in the $I30 index is removed, but remnants often persist in the slack space of INDX records within the $INDEX_ALLOCATION. These residual entries can contain the filename and file reference number, allowing an analyst to infer the existence of a deleted file. The $BITMAP, $LOGGED_UTILITY_STREAM, and $REPARSE_POINT attributes do not store filename entries.

Exam trap

The trap here is assuming that deleted directory entries are completely erased and that only the $MFT can show deleted files, overlooking the residual data in INDX slack space.

217
MCQeasy

An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?

A.$STANDARD_INFORMATION timestamps are always more reliable than $FILE_NAME timestamps and should be used exclusively.
B.$FILE_NAME timestamps are only populated when a file is created and never change afterward.
C.$FILE_NAME timestamps are duplicates of $STANDARD_INFORMATION and can be ignored.
D.$STANDARD_INFORMATION and $FILE_NAME each contain four timestamps, and comparing them can reveal timestamp manipulation or file moves.
AnswerD

Both attributes hold creation, modification, MFT change, and access times. Because they are updated by different code paths, discrepancies between them can indicate timestomping or a file move or rename, making both sets valuable for a defensible timeline.

Why this answer

NTFS stores timestamps in both the $STANDARD_INFORMATION and $FILE_NAME attributes of an MFT record. The two sets are maintained by different mechanisms and can disagree, which is itself valuable evidence. An analyst should extract both and compare them rather than relying on a single source, because the discrepancies often indicate moves, renames, or deliberate timestamp alteration.

Exam trap

The trap here is treating one attribute's timestamps as authoritative and ignoring the other, which discards corroborating or contradictory evidence.

218
MCQmedium

An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Which event ID should the analyst examine to find this information?

A.4625
B.4647
C.4624
D.4634
AnswerC

Event ID 4624 is logged when a logon attempt succeeds. It includes the logon type, which indicates the type of logon (e.g., interactive, network, batch). For interactive logons, the logon type is 2 (Interactive) or 10 (RemoteInteractive). By filtering for these logon types and the specific user, the analyst can determine the last interactive logon time.

Why this answer

Event ID 4624 is the primary event for successful logons. It contains detailed information including the logon type, which distinguishes interactive (type 2 or 10) from network (type 3) or other logons. By filtering for the specific user account and logon types 2 and 10, the analyst can identify the most recent interactive logon.

This is a standard technique in Windows forensic analysis.

Exam trap

The trap here is confusing logon events with logoff events or failed logon events; only 4624 records successful logons, and the logon type must be considered to isolate interactive sessions.

219
MCQmedium

During an enterprise incident response, you are examining evidence on a Windows Server 2019 system that may contain a fileless malware infection. You need to determine whether a specific process was injected with malicious code. Which Windows forensic artifact is most directly useful for identifying anomalous memory regions in a process, such as those created by reflective DLL injection?

A.MFT (Master File Table) entries
B.Memory dump of the process
C.Prefetch files
D.Windows Event Log Security log
AnswerB

A memory dump captures the full contents of a process's virtual address space, including loaded modules, heaps, stacks, and any injected code. By analyzing the dump with tools like Volatility or WinDbg, you can identify memory regions that are not backed by a file on disk (e.g., PAGE_EXECUTE_READWRITE) and detect reflective DLL injection. This directly addresses the need to find anomalous memory regions.

Why this answer

Reflective DLL injection loads a DLL directly into memory without writing it to disk, so disk-based artifacts like Prefetch or MFT entries will not show the injected code. A process memory dump captures the actual memory contents, allowing the analyst to spot anomalous regions such as executable memory not backed by a file. This makes the memory dump the most direct and reliable artifact for this scenario.

Exam trap

The trap here is assuming that disk-based execution artifacts like Prefetch or MFT entries can reveal in-memory code injection.

220
MCQeasy

An organization's incident response plan includes a requirement to maintain chain of custody for all digital evidence. A security analyst collects a USB drive from a compromised workstation. Which of the following is the MOST critical action to perform to ensure the evidence is admissible in a court of law?

A.Document the collection details, including date, time, location, and collector's name.
B.Store the USB drive in a secure, locked cabinet with limited access.
C.Create a forensic image of the USB drive using a write-blocker.
D.Analyze the USB drive immediately to identify the attacker.
AnswerA

Chain of custody documentation is essential for admissibility. It records the who, what, when, where, and why of evidence collection and transfer. Without proper documentation, the evidence can be challenged as tampered or unauthenticated. This is the most critical step to maintain integrity and admissibility.

Why this answer

Chain of custody is a legal concept that documents the seizure, custody, control, transfer, analysis, and disposition of evidence. Proper documentation from the moment of collection is crucial to prove that the evidence has not been tampered with. This documentation includes details such as date, time, location, collector, and any transfers.

Without it, the evidence may be deemed inadmissible.

Exam trap

The trap here is focusing on technical preservation steps like imaging or secure storage, but the legal requirement for admissibility hinges on documented chain of custody.

221
MCQhard

During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?

A.The parent process has terminated, and the PPID is now stale.
B.The memory dump is corrupted and the process list is incomplete.
C.The process 'svchost.exe' is a known Windows service and its parent should always be 'services.exe'.
D.The PPID indicates that the parent process is hidden by a rootkit and should be recovered using psscan.
AnswerA

In Windows, when a parent process terminates, its child processes are not terminated. The PPID of a child remains pointing to the now-defunct parent PID. Since PID 1234 is not in the active process list, it likely terminated, leaving a stale PPID. This is a common forensic artifact and does not necessarily indicate malicious activity.

Why this answer

When a parent process terminates, its child processes continue to run, and the child's PPID remains set to the now-invalid parent PID. This results in a stale PPID. The absence of PID 1234 in the active process list indicates that the parent has likely terminated, which is a normal occurrence and not inherently malicious.

Exam trap

The trap here is assuming that a missing parent process automatically indicates a hidden process or rootkit, when it is often just a terminated parent.

222
Multi-Selecthard

An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)

Select 2 answers
A.Security Event ID 4624 with Logon Type 3
B.UserAssist registry keys
C.Prefetch files for the remote access client
D.Security Event ID 5140 for a network share object
E.Sysmon Event ID 3 (Network Connection)
AnswersA, D

Security Event ID 4624 with Logon Type 3 indicates a network logon, which occurs when a user accesses a remote share. It records the account name, logon time, and source network address. This directly evidences remote file share access, making it a primary artifact for the scenario.

Why this answer

Security Event ID 4624 with Logon Type 3 and Event ID 5140 both directly record network logons and share access, respectively. They provide the account, timestamp, and share details needed to prove a user accessed a remote share. The other artifacts lack the specificity to directly evidence this activity.

Exam trap

The trap here is assuming that network connection logs or execution artifacts can prove file share access, when only specific security events like 4624 Type 3 and 5140 capture the account and share details.

223
Multi-Selecthard

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Select 2 answers
A.windows.dlllist
B.windows.ldrmodules
C.windows.vadinfo
D.windows.handles
E.windows.malfind
AnswersC, E

The windows.vadinfo plugin lists virtual address descriptors (VADs) for a process, showing memory regions and their protections. It helps identify unusual memory allocations, such as those with execute permissions that are not backed by a file, which are indicative of injected code. It complements malfind by providing detailed VAD information.

Why this answer

The windows.malfind and windows.vadinfo plugins are both designed to analyze process memory for suspicious regions. malfind identifies and dumps potentially injected code based on memory protection and file backing, while vadinfo provides a detailed view of all VADs, helping analysts spot anomalous memory allocations that may contain injected code.

Exam trap

The trap here is assuming that any plugin listing DLLs or handles will detect code injection, when injection often involves non-DLL memory regions.

224
Multi-Selecthard

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

Select 2 answers
A.Processes present in windows.psscan but absent in windows.pslist are likely hidden by rootkit activity.
B.windows.psscan may report processes that have already terminated but whose EPROCESS structures have not been overwritten.
C.Processes present in windows.pslist but absent in windows.psscan indicate that the process terminated normally and its memory was freed.
D.If windows.psscan and windows.pslist produce identical output, it definitively proves that no rootkit is present on the system.
E.windows.pslist relies on pool tag scanning, while windows.psscan walks the active process list.
AnswersA, B

windows.psscan uses pool tag scanning to find EPROCESS structures regardless of whether they are linked in the active list. If a process appears in psscan but not pslist, it suggests the process was unlinked, a common rootkit technique. This discrepancy is a key indicator of hidden processes, making this statement correct.

Why this answer

The correct statements highlight that windows.psscan can reveal processes hidden from the active list and may also report terminated processes whose structures remain. These behaviors are essential for detecting rootkits that unlink processes. The other statements contain factual errors about the tools' methods or draw unsupported conclusions from identical output.

Exam trap

The trap here is assuming that any discrepancy between pslist and psscan automatically indicates malicious activity, when psscan can also report terminated processes or false positives due to memory reuse.

225
MCQeasy

An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot be taken offline. Which method is most appropriate for acquiring the disk image while minimizing disruption?

A.Use a hardware write blocker and remove the disk to image it on a separate workstation.
B.Use a live acquisition tool like FTK Imager or Magnet ACQUIRE to create a forensic image of the disk while the system is running.
C.Run the built-in Windows backup utility to create a system image to a network share.
D.Use diskpart to create a shadow copy and then copy the volume to an external drive.
AnswerB

Live acquisition tools such as FTK Imager or Magnet ACQUIRE can create a forensic image of the disk without taking the server offline. They capture the disk contents while the system is running, minimizing disruption. This is the most appropriate method for a critical server that cannot be shut down, though it may not capture volatile data, so that should be collected separately.

Why this answer

For a running server that cannot be taken offline, live acquisition with a tool like FTK Imager or Magnet ACQUIRE is the best option. These tools create a forensic image of the disk while the system is operational, preserving the data with minimal disruption. However, they should be used in conjunction with volatile data collection to capture memory and network state.

Exam trap

The trap here is assuming that any backup or shadow copy method is forensically sound, when only specialized live acquisition tools preserve the necessary integrity and completeness.

Page 2

Page 3 of 4

Page 4

All pages