Courseiva

GIAC Certified Forensic Analyst (GCFA) — Questions 226–292

292 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
Multi-Selectmedium

During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)

Select 2 answers
A.Capture the contents of physical memory (RAM) using a tool like WinPmem or DumpIt.
B.Export the Windows Event Logs to a secure location.
C.Take screenshots of the desktop and open applications.
D.Create a forensic image of the system drive using FTK Imager or dd.
E.Record active network connections and listening ports using netstat -anob.
AnswersA, E

Physical memory is the most volatile evidence and contains running processes, network connections, and encryption keys. Capturing it first preserves data that would be lost on shutdown or reboot. Tools like WinPmem or DumpIt create a forensic image of RAM that can later be analyzed for artifacts not found on disk, making this a critical first step in volatile evidence collection.

Why this answer

The order of volatility dictates that physical memory and active network connections are the most perishable. Capturing RAM preserves running processes and encryption keys, while recording network connections captures transient command-and-control activity. These two actions must be performed first to prevent loss of critical evidence before moving to less volatile sources like disk images or event logs.

Exam trap

The trap here is assuming that disk imaging or event log export should be done first because they are commonly emphasized, but they are less volatile than RAM and network state.

227
MCQmedium

Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?

A.It is an application log that tracks system crashes.
B.It holds the metadata for all files on the volume.
C.It stores user credentials for encrypted files.
D.It is only used to store files larger than 1GB.
AnswerB

The MFT acts as the central index of the NTFS file system. It contains critical metadata like timestamps and data pointers for every file. This is the foundation of digital forensic file analysis, enabling investigators to recover evidence of files, even after they have been deleted by users.

Why this answer

The MFT is the central database of an NTFS volume. It stores metadata for every file and directory on the disk, including file names, sizes, timestamps, and data runs. For forensic analysts, the MFT is the most important artifact, as it provides a comprehensive map of all files, including deleted ones, allowing for the reconstruction of the file system and identification of malicious files that were intentionally erased by an adversary.

Exam trap

Candidates often describe the MFT as the file data itself, rather than a metadata index, failing to distinguish between the file's contents and the record that describes the file.

228
MCQhard

An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?

A.The unbacked regions are likely legitimate DLLs loaded from disk but with modified permissions due to process hardening.
B.The unbacked regions are indicative of injected code or shellcode, as they do not correspond to any file on disk and have suspicious permissions.
C.The unbacked regions are artifacts of the Volatility plugin itself, which may incorrectly report memory as unbacked due to parsing errors.
D.The unbacked regions are likely due to memory compression or paging, where the file backing was temporarily removed from the working set.
AnswerB

Unbacked memory regions with PAGE_EXECUTE_READWRITE and MZ headers are classic signs of code injection. Legitimate executables and DLLs are backed by files on disk. The absence of a file mapping indicates the code was placed directly into memory, often by process injection techniques. This is a key finding in fileless malware investigations and warrants further analysis of the injected content.

Why this answer

In memory forensics, unbacked memory regions with PAGE_EXECUTE_READWRITE protection and executable content such as an MZ header strongly suggest injected code or shellcode. Legitimate code is typically backed by a file on disk via a mapped section. The lack of file backing means the code was likely written directly into the process's address space by an injection technique, a common characteristic of fileless malware.

This finding should prompt further extraction and analysis of the injected payload.

Exam trap

The trap here is assuming that unbacked RWX regions are benign due to memory management quirks like paging, when they are actually a primary indicator of code injection in fileless attacks.

229
MCQhard

An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?

A.SRUM (System Resource Usage Monitor)
B.Amcache.hve
C.Prefetch files
D.UserAssist
AnswerC

Prefetch files are created when an executable is run, and they record execution time and run count. If a Prefetch file exists for the malicious executable, it confirms that the program was executed on the system. ShimCache only indicates that the file was present and may have been executed, so Prefetch provides the necessary confirmation.

Why this answer

Prefetch files are created by the Windows Cache Manager when an executable is run, recording the execution time and run count. This directly confirms execution. ShimCache only shows that a file was present and may have been executed, so Prefetch is the best additional artifact to verify execution.

Amcache, UserAssist, and SRUM may provide supporting evidence but are not as definitive or comprehensive for this purpose.

Exam trap

The trap here is assuming that Amcache or ShimCache alone can prove execution, but they only show file presence or metadata; Prefetch is the artifact that definitively confirms execution.

230
MCQhard

A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?

A.windows.pslist will show more processes than windows.psscan because it includes terminated processes that are still in memory.
B.windows.psscan will show more processes than windows.pslist because it can detect processes that have been unlinked from the active process list.
C.Both plugins will show the same number of processes because they both use the same underlying data structure.
D.windows.psscan will show fewer processes than windows.pslist because it relies on a linked list that the rootkit modifies.
AnswerB

windows.psscan scans physical memory for process objects using pool tag scanning, independent of the active process list. A rootkit that unlinks a process from the list will hide it from windows.pslist, but the process object may still reside in memory and be detected by windows.psscan. Therefore, windows.psscan is likely to show more processes, revealing the hidden one.

Why this answer

windows.pslist enumerates processes by following the active process list, which a rootkit can manipulate by unlinking its process. windows.psscan, however, scans memory for process objects using pool tags, which does not rely on the list. Therefore, in the presence of a process-unlinking rootkit, windows.psscan will detect the hidden process, resulting in a higher process count compared to windows.pslist. This discrepancy is a key indicator of hidden processes.

Exam trap

The trap here is assuming that both plugins rely on the same process list and would show identical results, missing that windows.psscan uses independent memory scanning to uncover unlinked processes.

231
Multi-Selecthard

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Select 2 answers
A.The process's token indicates it is running with elevated privileges.
B.The process's image path in memory does not match the file path on disk.
C.The process's parent process ID (PPID) is a non-existent process.
D.The process has a thread start address that points to a memory region not backed by a file on disk.
E.The process has a large number of open handles to remote named pipes.
AnswersB, D

In process hollowing, the original executable is created in a suspended state, its memory is unmapped, and malicious code is injected. The in-memory image path (from the PEB) may still point to the original file, but the actual code in memory is different. A mismatch between the in-memory image path and the on-disk file path, or a discrepancy in the code, is a strong indicator. This is often detected by comparing the in-memory module with the disk file.

Why this answer

Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, and injecting malicious code. This results in two key indicators: the in-memory image path may not match the disk file (or the memory content differs from disk), and threads execute from memory regions not backed by a file. These artifacts are directly tied to the hollowing technique and are detectable through memory analysis.

Exam trap

The trap here is focusing on generic indicators like elevated privileges or missing parent processes, which are not specific to process hollowing, rather than the memory-centric artifacts that directly reveal the technique.

232
MCQmedium

An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?

A.The record only shows that the file was opened for read access, because DATA_OVERWRITE is logged when the data stream is read.
B.The record indicates only that the file's MFT metadata was updated, not that the file data stream changed.
C.The record confirms the file was deleted and then re-created with the same name at the recorded time.
D.The record proves the file's data stream was overwritten at the time of the USN entry and can anchor the timeline for content modification.
AnswerD

DATA_OVERWRITE (0x00000100) indicates that data in the file was overwritten at the recorded time. Because the USN journal is written when the change occurs, this record is a reliable anchor for content modification on the timeline, assuming the journal has not wrapped and overwritten older records.

Why this answer

USN journal records capture specific change reasons at the moment they occur, and DATA_OVERWRITE specifically denotes that file data was overwritten. When the journal is intact and not wrapped, this gives the investigator a strong anchor for content modification. Other flags correspond to metadata or lifecycle events, so the reason code must be read literally.

Exam trap

The trap here is assuming any USN record reflects a content change rather than reading the specific Reason flag.

233
MCQmedium

An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?

A.Check the system's DNS cache for the remote IP to see if it resolves to a known domain, which would confirm whether the connection is benign.
B.Immediately block the remote IP at the firewall and terminate the chrome.exe process, as an established connection to an external IP on port 443 is highly suspicious.
C.Correlate the remote IP with threat intelligence feeds and examine the process memory for injected code or unusual strings.
D.Run 'vol.py -f memory.dmp windows.dlllist --pid 1234' to list all loaded DLLs and check for any unsigned or suspicious modules.
AnswerC

The connection is from a legitimate process (chrome.exe) to a remote IP on port 443, which is common for HTTPS traffic. However, malware can inject into legitimate processes or use them to communicate with command-and-control servers. Correlating the IP with threat intelligence and examining the process memory for anomalies (e.g., injected code, suspicious strings) is the logical next step to determine if the connection is malicious. This approach balances the need to investigate without assuming benign or malicious.

Why this answer

When a network connection from a legitimate process like chrome.exe is observed, it is not inherently malicious. The analyst must gather more evidence. Correlating the remote IP with threat intelligence can indicate if it is known malicious.

Examining the process memory for injected code or unusual strings can reveal if the process has been compromised. This combination provides a stronger basis for determining the nature of the connection.

Exam trap

The trap here is assuming that a connection from a known legitimate process to an external IP on port 443 is automatically benign, or conversely, immediately malicious; both assumptions are premature without further investigation.

234
MCQmedium

When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?

A..pf
B..automaticDestinations-ms
C..log
D..lnk
AnswerB

The .automaticDestinations-ms extension is used for the files stored in the AutomaticDestinations folder. These files contain lists of recently accessed items for a specific application. Identifying these files allows an analyst to extract document names, folder paths, and timestamps related to the user's recent file interaction history.

Why this answer

Jump Lists, located in the AutomaticDestinations and CustomDestinations folders, track recently accessed files and applications. The files are identified by an AppID, which is a hash of the application's path. These files often end with the .automaticDestinations-ms extension.

They are vital for identifying files opened by users, providing insight into document access, media playback, and tool usage that may relate to intellectual property theft or evidence of work.

Exam trap

Candidates often assume all Jump List files share the same extension, failing to differentiate between the 'AutomaticDestinations' and 'CustomDestinations' naming conventions used by the operating system.

235
MCQhard

Which attribute is used to store the location and length of file data runs in an NTFS MFT record?

A.$FILE_NAME
B.$DATA
C.$INDEX_ROOT
D.$ATTRIBUTE_LIST
AnswerB

$DATA contains either the data itself (if resident) or the data runs (if non-resident). Data runs provide the logical-to-physical mapping required for the OS to retrieve file data from the disk clusters. This is the core attribute for mapping file content to disk-level storage locations.

Why this answer

The $DATA attribute is responsible for storing the file's content or references to the clusters where the data resides on the disk. When the file is too large to be resident, the $DATA attribute contains 'data runs'—compacted descriptions of the starting cluster and the number of consecutive clusters allocated to the file, which the driver uses to read the file data.

Exam trap

Candidates frequently confuse the $DATA attribute with $STANDARD_INFORMATION or $FILE_NAME when asked where non-resident file data runs and cluster locations are stored.

236
MCQmedium

When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?

A.Filtering increases the precision of the file system's internal clock
B.Filtering removes redundant entries to prevent system crashes during analysis
C.Filtering isolates relevant events from the massive volume of benign system activity
D.Filtering is required to encrypt the timeline output for secure storage
AnswerC

Super-timelines aggregate thousands of events, most of which are benign OS background tasks. Effective filtering narrows the scope to relevant timeframes or specific file types, enabling the analyst to quickly identify meaningful patterns of attacker behavior that would otherwise be obscured by the sheer volume of normal operating activity.

Why this answer

Super-timelines ingest massive amounts of data from diverse sources, including system logs, web history, and file system metadata. Without filtering, the volume of 'noise' from routine system activity makes it nearly impossible to isolate the specific events relevant to an incident. Filtering allows the investigator to focus on anomalous patterns and specific time windows, drastically increasing the efficiency and accuracy of the forensic reconstruction process during a high-pressure investigation.

Exam trap

Test-takers often assume raw super-timelines are self-explanatory, underestimating the overwhelming volume of benign noise that obscures actual malicious indicators.

237
MCQeasy

During an incident response engagement, you need to establish a timeline of adversary activity on a compromised Windows server. Which data source is most appropriate for correlating user logon events, service installations, and process executions?

A.Windows Event Logs
B.Registry hives
C.Prefetch files
D.File system metadata (MAC times)
AnswerA

Windows Event Logs, particularly Security, System, and Application logs, record logon events, service installations, and process creation (with appropriate auditing). They provide timestamps and details necessary for building a comprehensive timeline of adversary activity across multiple event types.

Why this answer

Windows Event Logs are the most comprehensive source for correlating diverse activities such as logons, service installations, and process executions. They provide a centralized, timestamped record that can be analyzed to reconstruct a timeline of adversary actions across the system, making them indispensable for incident response.

Exam trap

The trap here is assuming that file system metadata orPrefetch alone can provide a complete timeline, when they only cover specific types of activity.

238
MCQmedium

An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?

A.windows.dlllist
B.windows.handles
C.windows.threads
D.windows.malfind
AnswerC

windows.threads lists all threads for a given process, including thread IDs, start addresses, and stack information. This allows an analyst to identify threads whose start addresses fall outside the normal module range, which is a strong indicator of code injection. It directly addresses the requirement to examine threads and their start addresses in volatile memory, making it the correct choice.

Why this answer

The windows.threads plugin enumerates threads within a process, showing start addresses that can be compared against known module ranges. Injected threads often have start addresses in unbacked memory, making this plugin ideal for detecting code injection. The other plugins focus on memory regions, handles, or loaded modules, none of which provide thread-level detail needed to identify an injected thread.

Exam trap

The trap here is assuming that windows.malfind is always the best plugin for detecting code injection, but it only scans memory regions and does not enumerate threads or their start addresses.

239
MCQeasy

Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?

A.It is only updated if the file is moved to a different folder
B.It is unreliable due to frequent updates by system services
C.It is the most easily forged timestamp in the MFT
D.It only exists on FAT32 file systems
AnswerB

Access times are updated by nearly any process that reads a file, including security software, search indexers, and background tasks. This makes it impossible to distinguish between a malicious user accessing a document and a background service performing a routine scan, rendering the timestamp unreliable for proving intentional user interaction.

Why this answer

The 'Last Accessed' timestamp is notoriously unreliable in forensic analysis because it is frequently updated by non-human system activity, such as antivirus scans or indexing services. Furthermore, many systems have the 'noatime' option enabled, which stops the OS from updating this field entirely. Because of this noise and potential for total absence, relying on this value for evidence of user activity is inherently dangerous and prone to producing false positives.

Exam trap

Candidates often assume that 'Last Accessed' timestamps reliably indicate when a user opened a file, overlooking frequent background system updates and the 'noatime' filesystem setting.

240
MCQhard

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

A.The Master File Table (MFT)
B.The thread list in the scheduler
C.The user-mode Process Environment Block (PEB)
D.The System Service Descriptor Table (SSDT)
AnswerB

The Windows kernel scheduler relies on thread objects to allocate CPU time. Since the kernel must track every active thread to function, comparing the thread list against the EPROCESS list allows an analyst to find processes that have unlinked themselves from the active process list but are still running.

Why this answer

Cross-view analysis involves comparing the results of different enumeration methods to find inconsistencies. While the EPROCESS list (ActiveProcessLinks) is easily manipulated by rootkits to hide processes, the thread-based enumeration is much harder to hide, as the Windows scheduler must be aware of every thread to execute it. By iterating through all threads in the system, an analyst can identify processes that are excluded from the primary link list but are still actively executing.

Exam trap

Candidates often select the handle table or loaded module list, which are also easily manipulated by rootkits, failing to recognize that the scheduler's thread list is the most fundamental execution primitive.

241
MCQeasy

A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?

A.It stores the security descriptor for the file to control access permissions.
B.It lists the data runs for the $DATA attribute when the file is fragmented.
C.It tracks the change journal entries for the file for auditing purposes.
D.It provides a mapping of all attributes and their locations when they do not fit in the base MFT record.
AnswerD

The $ATTRIBUTE_LIST attribute is used when a file has many attributes or large attributes that cannot fit in the base MFT record. It lists the attributes and indicates whether they are resident in the base record or in an extension MFT record. This allows NTFS to locate all attributes of a file across multiple MFT records.

Why this answer

The $ATTRIBUTE_LIST attribute is present when a file's attributes cannot all fit in the base MFT record. It lists each attribute and specifies whether it is resident in the base record or in an extension record, along with the MFT reference of that extension record. This allows NTFS to locate all attributes.

The other options describe functions of other attributes or metadata files.

Exam trap

The trap here is confusing the $ATTRIBUTE_LIST with attributes that store data runs or security information, when it actually serves as an index for locating attributes across MFT records.

242
Multi-Selecthard

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Select 2 answers
A.pslist enumeration
B.psscan pool tag analysis
C.Handle table analysis
D.Task Manager API polling
E.Registry hive parsing
AnswersB, C

The psscan plugin searches for EPROCESS objects by scanning memory for specific pool tags. This method does not rely on the integrity of the linked list pointers, making it highly effective at finding processes that have been unlinked or hidden by malicious kernel-mode activity during the investigation.

Why this answer

Detecting hidden processes requires comparing results from multiple analysis techniques. Traversing linked lists (pslist) is easily bypassed, so analysts use pool tag scanning (psscan) and cross-referencing with other structures like the Handle Table. These methods are critical because they bypass standard OS reporting mechanisms, ensuring that malware hiding via DKOM or other techniques is identified by looking at the raw physical memory contents directly.

Exam trap

Candidates frequently rely exclusively on standard pslist output during memory analysis, failing to utilize pool tag scanning and handle tables to catch hidden processes.

243
Multi-Selectmedium

An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)

Select 2 answers
A.Reimage all affected servers immediately to restore business operations
B.Isolate affected servers from the network at the switch or EDR level while keeping them powered on
C.Immediately power off all affected servers to halt encryption activity
D.Capture a memory image of each affected server before any containment action
E.Delete all encrypted files to prevent the ransomware from spreading further
AnswersB, D

Network isolation via switch ACLs or EDR containment stops lateral spread and command-and-control communication while preserving volatile memory, running processes, and active sessions for forensic capture. It maintains system state for memory acquisition and allows the team to collect live evidence before any shutdown, satisfying both containment and preservation goals.

Why this answer

Isolating affected servers at the network layer stops the spread without destroying volatile evidence, and capturing memory before containment preserves fragile artifacts such as encryption keys and active processes. Together they satisfy containment and preservation. Powering off, reimaging, or deleting files would destroy evidence or recovery options and do not represent a balanced response.

Exam trap

The trap here is equating containment with immediate shutdown or reimaging, when those actions destroy the volatile evidence that ransomware investigations depend on.

244
MCQhard

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?

A.The file is a sparse file, and the 0-byte size indicates that all its data is stored in sparse regions.
B.The file's data runs point to clusters that have been marked as bad and are no longer accessible.
C.The file's $DATA attribute has a logical size of 0 but still has allocated clusters, indicating possible slack space or hidden data.
D.The $DATA attribute is corrupted, and the file system is reporting an incorrect size.
AnswerC

In NTFS, a non-resident $DATA attribute can have a logical size of 0 while still having allocated clusters if the file was truncated or if data was written and then the size was reset without deallocating clusters. This can be used to hide data in allocated clusters that are not reflected in the file size. Forensic tools can examine the data runs to recover such hidden data.

Why this answer

A non-resident $DATA attribute with a logical size of 0 but allocated clusters is a classic sign of data hiding. An attacker can write data to a file, then truncate the file's logical size to 0 without deallocating the clusters, leaving the data intact in the allocated clusters. Forensic tools can parse the data runs and recover the hidden content.

This technique is often used to conceal data on NTFS volumes.

Exam trap

The trap here is assuming that a 0-byte file size means no data exists, when in fact allocated clusters may still contain hidden data.

245
MCQeasy

An incident responder is reviewing logs from a compromised Linux server and notices a large number of failed SSH login attempts from a single external IP address, followed by a successful login. Which of the following best describes this activity?

A.A misconfigured SSH client repeatedly attempting to authenticate with an expired key.
B.A denial-of-service attack that overwhelmed the SSH service.
C.A brute-force attack that resulted in unauthorized access.
D.A legitimate user who forgot their password and eventually guessed it correctly.
AnswerC

The pattern of many failed SSH logins followed by a successful one is characteristic of a brute-force attack. The attacker likely used a tool like Hydra or Medusa to guess credentials. The successful login indicates that the attacker gained access, which is a critical security incident. The responder should investigate the source IP, check for additional compromised accounts, and review what the attacker did after logging in.

Why this answer

The sequence of numerous failed SSH logins from a single external IP followed by a successful login is a classic indicator of a brute-force attack that succeeded. This constitutes unauthorized access and requires immediate incident response actions, including isolating the server, investigating the attacker's activities, and resetting compromised credentials.

Exam trap

The trap here is dismissing the failed logins as a misconfiguration or a forgetful user, when the external source and eventual success indicate a brute-force attack.

246
MCQmedium

A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?

A.The windows.cmdline plugin output from the memory image showing the PowerShell process command line.
B.Windows Security event log, event ID 4688 (Process Creation) with command-line auditing enabled.
C.The windows.pslist plugin output showing the PowerShell process and its parent process.
D.Windows PowerShell event log, event ID 4104 (Script Block Logging).
AnswerD

Event ID 4104 in the Windows PowerShell operational log records the actual script block text when Script Block Logging is enabled. This directly captures the PowerShell code that was executed, including obfuscated or dynamically generated content, making it the most direct source for reconstructing the malicious script block. It is not enabled by default, so its presence indicates prior configuration.

Why this answer

Script Block Logging (event ID 4104) captures the actual PowerShell code that runs, including obfuscated or dynamically constructed script blocks, and writes it to the Windows PowerShell operational log. This is the most direct artifact for determining what a malicious PowerShell script did. Command-line auditing and memory plugins can show how PowerShell was launched but not the full script content.

Therefore, the PowerShell event log with 4104 is the best source.

Exam trap

The trap here is assuming that command-line auditing or memory command-line plugins capture the full PowerShell script, when they only show how the process was started and not the script blocks executed at runtime.

247
MCQeasy

In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?

A.The difference between local time and UTC
B.The intentional modification of a file's timestamp
C.The discrepancy between the system clock and the actual time
D.The process of normalizing timestamps to a common format
AnswerC

Time skew represents the drift or offset of a system clock compared to an accurate reference time. It is a critical factor for forensic analysts to document; failing to account for it will result in an incorrect sequence of events when comparing the evidence against other system logs or external timestamps.

Why this answer

Time skew is the difference between the actual wall-clock time and the time reported by the system under investigation. Identifying and correcting for this skew is a fundamental prerequisite for timeline analysis. If the investigator ignores the skew, all events will be chronologically misaligned, making it impossible to correlate evidence across different machines or correlate logs with file system activity during the incident reconstruction phase.

Exam trap

Candidates often treat the system time as absolute truth, failing to account for the drift between the local machine clock and the actual UTC time during multi-system correlation.

248
MCQmedium

During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?

A.The memory region is likely a legitimate dynamically allocated buffer used by explorer.exe for temporary data storage.
B.The memory region is likely a memory-mapped file that was paged out and later paged back in without file backing due to a system error.
C.The memory region is a false positive because windows.malfind often flags legitimate JIT-compiled code from .NET applications.
D.The memory region indicates that explorer.exe has been injected with malicious code, as it exhibits characteristics of process hollowing or reflective DLL injection.
AnswerD

PAGE_EXECUTE_READWRITE memory containing a PE header and not backed by a file is a classic indicator of code injection. Malware often uses techniques like reflective DLL injection or process hollowing to execute code within a legitimate process. The lack of file backing means the code was not loaded from disk, further supporting malicious injection.

Why this answer

A memory region with PAGE_EXECUTE_READWRITE protection, containing a PE header, and not backed by a file is a strong indicator of code injection. Legitimate processes rarely allocate such memory, and the presence of a PE header suggests a portable executable was loaded directly into memory. This is consistent with techniques like reflective DLL injection or process hollowing, where malicious code is executed within a trusted process to evade detection.

Exam trap

The trap here is dismissing the finding as a false positive due to legitimate JIT or memory-mapped files, ignoring that unbacked executable memory with a PE header is a hallmark of injection.

249
MCQeasy

A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?

A.The $UsnJrnl:$J alternate data stream, which logs USN_RECORD entries including RENAME_OLD_NAME and RENAME_NEW_NAME reasons.
B.The $MFT's $FILE_NAME attribute, which stores a history of all previous names assigned to the file.
C.The $Secure:$SDS stream, which records security descriptor changes that occur during rename operations.
D.The $LogFile, which contains redo and undo records for all metadata transactions including filename changes.
AnswerA

The USN change journal records file system events with reason flags such as RENAME_OLD_NAME and RENAME_NEW_NAME, and each record includes the filename at the time of the event. Querying $UsnJrnl:$J can reveal the prior name and the sequence of renames, which the $STANDARD_INFORMATION timestamps alone cannot show.

Why this answer

The USN change journal, stored in the $UsnJrnl:$J alternate data stream, records file system events with reason codes. RENAME_OLD_NAME and RENAME_NEW_NAME entries capture both the prior and current filenames along with a timestamp and the file reference number. This makes the USN journal the primary artifact for reconstructing rename activity on NTFS.

Exam trap

The trap here is assuming the $LogFile or $MFT retains historical filenames, when only the USN change journal systematically records rename events with old and new names.

250
MCQmedium

During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?

A.The Security event log entry 4624 with Logon Type 2 recorded at the time of the incident
B.The NTUSER.DAT registry hive loaded in the user's profile folder
C.The Security event log entry 4634 recording a logoff event
D.The Security event log entry 4647 recording a user-initiated logoff
AnswerA

Event ID 4624 with Logon Type 2 indicates an interactive logon at the console, recorded in the Security log at the moment the session was established. In this scenario it directly ties a specific account to a physical or console session, making it the most reliable artifact for confirming who was actively logged in at the time of the incident.

Why this answer

An interactive logon is recorded as Security event 4624 with Logon Type 2, which is generated when a user authenticates at the console. Because the question asks who was actively logged on at the moment of the incident, that specific logon type is the most direct and reliable evidence, whereas logoff entries and profile hives persist or indicate termination rather than active presence.

Exam trap

The trap here is assuming that the presence of a user profile hive such as NTUSER.DAT proves an active interactive session, when it only proves the profile was loaded at some point.

251
MCQmedium

When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?

A.The process is a system idle thread.
B.The process was likely orphaned by its parent.
C.The memory dump is corrupted.
D.The process is a legitimate background service.
AnswerB

Orphaned processes occur when the parent process has terminated. In forensic analysis, this is frequently seen with malware that uses a launcher process to execute a payload and then exits. It serves as a significant indicator of potential malicious activity, warranting a deeper look at the process's creation time.

Why this answer

A process with a non-existent parent ID often points to a 'orphaned' process, which is common when the parent process has already exited or was hidden. This is a red flag for malicious activity, as rootkits or malware often spawn sub-processes and then terminate the parent to hide the chain of execution. Identifying this is key to reconstructing the infection vector and timeline during a forensic investigation.

Exam trap

Candidates often assume a non-existent parent process ID indicates a system corruption error rather than investigating potential parent-child process spoofing or orphan processes.

252
MCQhard

An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?

A.The ext4 journal aggressively overwrites inode metadata before user-space tools can parse the raw blocks.
B.The operating system automatically randomizes inode timestamps every 24 hours to prevent precise profiling.
C.Mount options such as relatime or noatime suppress continuous updates to file access timestamps to improve performance.
D.The Sleuth Kit parser inherently misinterprets the 64-bit epoch time structures utilized by modern Linux kernels.
AnswerC

Performance tuning options like relatime update access times only if the previous access time is older than the modification time or if it has been over a day. This intentional kernel behavior hides casual file reads, undermining traditional timeline analysis techniques used in incident response.

Why this answer

The ext4 file system supports the noatime mount option, which disables the updating of access times whenever files are read. This optimization significantly reduces disk I/O overhead but blinds investigators to critical file access timelines, making it difficult to prove whether a specific binary was actually executed by a local user.

Exam trap

Students frequently rely blindly on file access timestamps without checking file system mount options, leading to false assumptions about user activity.

253
MCQhard

An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?

A.The Security event log records in the memory image
B.The Windows Prefetch file for the injected process
C.The process's virtual address descriptor (VAD) tree and associated memory sections
D.The MFT record for the deleted executable
AnswerC

The VAD tree describes each memory region mapped into the process, including private committed pages and mapped image sections. Injected code often appears as a private, executable region not backed by a file on disk. Analyzing VAD nodes and their page protections reveals suspicious executable regions and can identify the originating module even if the file was deleted.

Why this answer

The VAD tree is the memory structure that tracks every mapped region in a process, including private executable pages typical of code injection. Because injected code is often not backed by a file on disk, the VAD metadata is the most direct way to identify the anomalous region. Other artifacts like MFT records, Prefetch, or event logs may provide context but do not contain the injected code or its originating module.

Exam trap

The trap here is assuming that deleted-file artifacts such as MFT records or Prefetch files can reveal injected code, when injection lives in memory and is best exposed through the process VAD tree.

254
MCQmedium

What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?

A.It stores full file content for every transaction.
B.It has a much longer retention period.
C.It is not volatile and survives power loss.
D.It contains the actual NTFS security descriptors.
AnswerB

The $UsnJrnl is designed to track volume changes for administrative purposes, leading to a much larger storage capacity compared to the circular, high-frequency $LogFile. This allows analysts to view long-term trends and historical file operations, which is crucial for reconstructive analysis during an incident response engagement.

Why this answer

The $UsnJrnl (Update Sequence Number Journal) is designed to track changes to files and directories over a long period. Unlike the $LogFile, which is a circular, short-term buffer for atomicity and recovery, the $UsnJrnl maintains a more persistent record of file activity. This makes it an invaluable source of historical metadata for investigators tracking how files were modified, created, or deleted over weeks or months.

Exam trap

Candidates often confuse the $UsnJrnl with the $LogFile, assuming both serve the same short-term recovery purpose rather than recognizing the UsnJrnl's long-term persistence advantage.

255
MCQhard

An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?

A.The file is encrypted, and the data runs are stored in the $EFS attribute instead of $DATA.
B.The file's data runs are corrupt or the MFT entry is inconsistent, possibly due to disk corruption or deliberate manipulation.
C.The file is sparse, and the data runs include sparse ranges that map to clusters not physically allocated.
D.The file is compressed, and the data runs are stored in a separate $DATA attribute named $TXF_DATA.
AnswerB

If a file's non-resident $DATA attribute points to clusters that are currently allocated to another file, this indicates an inconsistency in the file system metadata. This can occur from disk corruption, software bugs, or deliberate tampering. It is not a normal state for any standard NTFS feature.

Why this answer

A non-resident $DATA attribute with data runs pointing to clusters allocated to another file is an abnormal condition. Standard NTFS features like compression, sparse files, or encryption do not cause such overlap. This inconsistency suggests corruption or intentional manipulation, requiring further forensic examination to determine the cause and potential data recovery challenges.

Exam trap

The trap here is attributing the cluster overlap to a standard NTFS feature like compression or sparse files, when it actually indicates metadata corruption or tampering.

256
MCQmedium

When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?

A.Event ID 4100
B.Event ID 4103
C.Event ID 4104
D.Event ID 400
AnswerC

Event ID 4104 logs the script block content executed by the PowerShell engine. This is the primary event for forensic analysis of PowerShell activity, as it captures the full script, including base64-encoded commands, allowing analysts to decode and analyze the malicious logic used in fileless attacks.

Why this answer

Event ID 4104 records the execution of a script block. Attackers frequently use PowerShell's -EncodedCommand parameter to bypass simple string-based signature detection. By analyzing the content of these logs, specifically looking for long, base64-encoded strings, analysts can decode the hidden payloads and reconstruct the attacker's actions, which is vital for understanding the full scope of a fileless attack that avoids traditional disk-based indicators.

Exam trap

Candidates frequently confuse Event ID 4104 (Script Block Logging) with Event ID 4103 (Module Logging) or process creation events like 4688 when looking for PowerShell execution patterns.

257
MCQmedium

You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?

A.windows.modscan
B.windows.modules
C.windows.driverscan
D.windows.driverirp
AnswerA

windows.modscan scans kernel pool memory for module structures and can identify modules that were loaded and later unloaded, because their metadata may remain in pool even after removal from the active module list. This directly addresses the need to find previously loaded drivers that are no longer active, making it the correct plugin for this scenario.

Why this answer

To find drivers that were loaded and then unloaded, you need a plugin that scans kernel pool for module structures rather than relying on the active PsLoadedModuleList. windows.modscan performs exactly that pool scan and can recover residual module metadata, whereas the other plugins either list only active modules or focus on driver objects and IRP hooks, which would not reliably surface an unloaded driver.

Exam trap

The trap here is assuming that windows.modules will show all drivers that were ever loaded, when in fact it only shows currently loaded modules and misses unloaded ones.

258
MCQmedium

Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?

A.Event ID 4624 with Logon Type 10.
B.Event ID 4672 during the authentication process.
C.Event ID 4648 involving the use of explicit credentials.
D.Event ID 4720 occurring at the same time.
AnswerA

Logon Type 10 is the specific identifier for Remote Interactive logins, typically associated with RDP connections. This is the primary forensic artifact used to distinguish human-driven remote access from automated system tasks or background service authentication, which use different logon types within the Windows event auditing subsystem.

Why this answer

The Windows Security Event log captures specific Logon Types that categorize the nature of the authentication. Logon Type 2 denotes an interactive local login, while Type 10 identifies Remote Interactive (RDP) sessions. Scheduled tasks typically utilize Type 4 (Batch) or Type 5 (Service), allowing analysts to differentiate between user-driven activity and automated system processes through forensic inspection of the event data.

Exam trap

Examinees often confuse interactive remote RDP sessions (Logon Type 10) with standard local interactive logins (Logon Type 2) or network services.

259
MCQhard

Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?

A.It encrypts the entire memory dump
B.It hides the process by unlinking it from the process list
C.It prevents the acquisition of the memory dump
D.It modifies the CPU instructions directly
AnswerB

The Windows API follows a doubly-linked list of process objects to enumerate running programs. By removing the process node from this list, a rootkit makes the process invisible to any tool using the API, even though the process continues to run because the scheduler still tracks it.

Why this answer

Traditional tools rely on the Windows API to list processes and threads. These APIs query the kernel's process list (ActiveProcessLinks). DKOM allows a rootkit to unlink a process from this list while leaving the process structure intact so it can still be scheduled for execution.

Because the API only reports what the kernel's linked list reveals, the hidden process effectively disappears from standard tools, requiring forensic analysts to use memory-parsing techniques.

Exam trap

Students often think standard task manager tools or Windows APIs can expose DKOM rootkits, forgetting that these APIs rely entirely on kernel-managed linked lists.

260
MCQhard

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

A.The process is running a standard, signed driver
B.The process has been infected via code injection
C.The process is using a standard heap allocation
D.The memory segment is a legitimate shared DLL
AnswerB

The 'MZ' signature identifies a portable executable file. Finding this header inside a memory segment that lacks file-backing and is set to RWX permissions confirms that a complete binary payload was injected into the process memory, which is a hallmark of sophisticated process injection attacks.

Why this answer

The presence of the 'MZ' header (the magic bytes for a Windows PE executable) in a memory region that is not backed by a file on disk (VadS) and is marked as PAGE_EXECUTE_READWRITE is definitive proof of an injected executable. The malware has loaded a complete, valid PE file directly into memory to run its payload, which is a classic indicator of advanced fileless malware that bypasses file-system-based security controls.

Exam trap

Candidates often mistake the presence of an MZ header for a simple file mapping, failing to notice that the memory region is private (not file-backed) and has suspicious RWX permissions.

261
MCQmedium

During a Windows 10 intrusion investigation, an analyst uses fls on a raw NTFS image and observes that for a suspicious executable, the $FILE_NAME creation timestamp is 2023-08-10 14:22:01, while the $STANDARD_INFORMATION creation timestamp is 2023-08-10 14:22:01 as well, but the $STANDARD_INFORMATION modified timestamp is 2023-08-10 14:22:01 and the $FILE_NAME modified timestamp is 2023-08-10 14:22:01. However, the $MFT record header's last modification time (the MFT entry itself) is 2023-08-10 14:25:33. What is the most likely explanation for the discrepancy between the MFT record modification time and the file's timestamps?

A.The system clock was changed at 14:25:33, causing the MFT record header to be updated while the file timestamps remained unchanged.
B.The file's attributes or MFT record structure were modified at 14:25:33, such as a change in the $DATA attribute or the addition of an alternate data stream, without altering the $STANDARD_INFORMATION or $FILE_NAME timestamps.
C.The file was accessed at 14:25:33, and the NTFS file system updates the MFT record header on every access.
D.The file was copied into the directory at 14:22:01, and the MFT record was later updated at 14:25:33 due to a backup operation.
AnswerB

The MFT record header timestamp is updated when the MFT entry itself is modified, such as when a new attribute is added, an attribute is resized, or the record is moved. Operations like adding an alternate data stream or changing the file's size can update the MFT record header without changing the $STANDARD_INFORMATION or $FILE_NAME timestamps, because those timestamps are stored in the attributes themselves. This explains the discrepancy while all file timestamps remain identical.

Why this answer

The MFT record header contains a timestamp that reflects when the MFT entry itself was last modified, which can occur independently of the file's $STANDARD_INFORMATION and $FILE_NAME timestamps. Operations such as adding an alternate data stream, resizing the $DATA attribute, or changing the file's name can update the MFT record header without altering the timestamps stored in the attributes. Thus, the discrepancy indicates a change to the MFT record structure, not a simple file access or copy.

Exam trap

The trap here is assuming that any MFT record header timestamp change necessarily corresponds to a change in the file's $STANDARD_INFORMATION or $FILE_NAME timestamps, when in fact the MFT record can be updated for structural changes that do not affect those attributes.

262
Multi-Selectmedium

An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)

Select 2 answers
A.Prefetch files showing that the Windows Credential Manager UI was launched by the user.
B.A memory image search for the 'sekurlsa' module strings and Mimikatz driver artifacts in non-paged pool.
C.Security Event ID 4688 process creation records showing the parent image of every long-running service.
D.Sysmon Event ID 10 records showing a process opening lsass.exe with GrantedAccess 0x1010 or 0x1410.
E.Amcache entries listing hashes of binaries installed under 'Program Files' on the host.
AnswersB, D

Residues of credential-dumping frameworks such as the sekurlsa module strings or the Mimikatz kernel driver can persist in memory after execution and are recoverable from a full memory capture. Finding them demonstrates the tooling was present and loaded on the host, which corroborates that LSASS memory was targeted even if the dumping process has already exited.

Why this answer

Establishing unauthorized LSASS access requires artifacts that either record the access event itself or demonstrate the presence of credential-dumping tooling. Sysmon process-access events capture the target process, requesting image, and granted access mask, while memory-resident strings and driver artifacts left by frameworks like Mimikatz show the tooling was loaded. Together they provide both the access event and the capability evidence.

Exam trap

The trap here is reaching for execution-history artifacts like Prefetch or Amcache, which prove a binary ran but say nothing about who opened LSASS memory or with what access mask.

263
MCQeasy

A forensic analyst is using a tool to generate a file system timeline from an NTFS volume. The tool outputs timestamps with nanosecond precision, but the analyst knows that NTFS stores timestamps with 100-nanosecond resolution. What is the most likely reason for the discrepancy?

A.The tool is incorrectly interpreting the timestamp format, treating them as nanoseconds instead of 100-nanosecond intervals.
B.The tool is reading timestamps from a different file system that stores nanosecond precision.
C.The tool is converting the 100-nanosecond intervals to nanoseconds and displaying additional precision that does not exist.
D.The NTFS file system on this volume has been upgraded to support nanosecond timestamps.
AnswerC

NTFS stores timestamps as 64-bit values representing the number of 100-nanosecond intervals since January 1, 1601. When a tool converts these to nanoseconds, it multiplies by 100, which can result in values that appear to have nanosecond precision but are actually limited to 100-nanosecond granularity. The extra digits are an artifact of conversion, not additional precision.

Why this answer

NTFS timestamps are stored as 64-bit values in 100-nanosecond intervals. When a forensic tool displays them, it often converts to nanoseconds for readability, which can introduce apparent nanosecond precision. The underlying resolution remains 100 nanoseconds, so the extra digits are not meaningful for timeline granularity.

Exam trap

The trap here is believing that the displayed precision reflects the actual storage resolution, leading to overconfidence in sub-100-nanosecond event ordering.

264
MCQeasy

An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?

A.It contains the full command-line arguments used when PowerShell was launched.
B.It indicates that PowerShell was installed as a service on the system.
C.It confirms that PowerShell was executed and provides the last execution time and number of times run.
D.It provides a list of all files accessed by PowerShell during its execution.
AnswerC

Prefetch files are created when an executable is run, and they record the last execution time and run count. The presence of a prefetch file for POWERSHELL.EXE indicates that PowerShell was executed on the system. The timestamp embedded in the .pf file can be parsed to determine the last execution time, which is valuable for timeline analysis.

Why this answer

The correct answer is that the prefetch file confirms execution and provides last execution time and run count. Prefetch files are created by the Windows Prefetcher to optimize application startup, and they include metadata such as the last run time and number of executions. This makes them a key artifact for determining if an executable like PowerShell was run, and when.

Exam trap

The trap here is assuming prefetch files store command-line arguments or complete file access lists, when they only provide execution metadata.

265
MCQeasy

A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?

A.The windows.cmdline plugin output showing the command line of cmd.exe.
B.The Windows Event Log 'Microsoft-Windows-CommandPrompt/Operational' with command history events.
C.The console history buffer in the conhost.exe process memory.
D.The PowerShell console history file at %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt.
AnswerC

The Windows Console Host (conhost.exe) maintains a history buffer of commands entered in a command prompt window. This buffer resides in the memory of the conhost.exe process associated with the console session. Extracting this buffer from a memory image can reveal recently typed commands that may not be recorded in any persistent log, making it a valuable volatile artifact for user activity.

Why this answer

The console history buffer in conhost.exe memory contains the commands typed in a command prompt window during the session. This volatile artifact is not written to disk by default, so it can only be recovered from a memory image. The PSReadLine history file is for PowerShell and is persistent, while event logs and cmdline plugins do not capture interactive command history.

Therefore, the conhost.exe buffer is the correct source.

Exam trap

The trap here is confusing PowerShell's persistent PSReadLine history file with cmd.exe console history, which is only held in conhost.exe memory and not saved to disk.

266
MCQmedium

An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?

A.Prefetch files in C:\Windows\Prefetch
B.UserAssist registry keys
C.Amcache.hve registry hive
D.Sysmon Event ID 1 (Process Creation) in the Windows Event Log
AnswerD

Sysmon Event ID 1 logs detailed process creation events, including the exact UTC timestamp, process GUID, image path, command line, and parent process ID. This directly answers when the process started and its parent-child relationship. If Sysmon was installed and configured, this is the most precise and reliable artifact for the scenario.

Why this answer

Sysmon Event ID 1 provides the most granular and reliable data for process creation, including exact timestamps and parent-child relationships. Other artifacts like Prefetch, Amcache, and UserAssist offer execution evidence but lack the precision and relationship details needed to reconstruct the sequence of events accurately.

Exam trap

The trap here is assuming that any execution artifact, such as Prefetch or Amcache, provides process creation timestamps and parent-child links, when only Sysmon Event ID 1 does so with the needed fidelity.

267
MCQeasy

A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?

A.The account is locked out and requires administrative intervention to unlock.
B.The system is experiencing a denial-of-service attack due to excessive failed logons.
C.An attacker has successfully brute-forced the user's password after multiple attempts.
D.The user mistyped their password several times before successfully logging in.
AnswerD

Multiple failed logon attempts followed by a successful logon for the same account often indicate a user who forgot their password or made typographical errors. While this could also indicate a brute-force attack, the pattern alone without other indicators (like many different accounts or high volume) is most consistent with normal user error.

Why this answer

The correct answer identifies that a few failed logons followed by a success are commonly caused by a user mistyping their password. This pattern is benign in isolation. Analysts should consider context, such as the number of attempts and source of logons, to differentiate from brute-force attacks.

Exam trap

The trap here is immediately assuming malicious brute-force activity without considering the volume and context of the failed attempts.

268
MCQeasy

An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?

A.netstat -tulpn
B.cat /etc/passwd | grep ':0:'
C.ps aux | grep root
D.ls -la /home
AnswerB

The /etc/passwd file contains user account information, with fields separated by colons. The third field is the UID. Searching for ':0:' will match any line where the UID is 0, which is typically only root. This command quickly reveals any additional accounts with root privileges, such as the malicious 'support' account. It is a simple and effective way to detect unauthorized UID 0 accounts.

Why this answer

The /etc/passwd file stores user account details, including the UID in the third field. Searching for ':0:' isolates accounts with UID 0, which have root privileges. This quickly uncovers any unauthorized root-equivalent accounts created by an attacker.

Other commands like ls, ps, or netstat do not provide UID information and would not detect the malicious account.

Exam trap

The trap here is assuming that only the 'root' account can have UID 0, when in fact any account can be assigned UID 0.

269
Multi-Selecthard

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Select 2 answers
A.Application Event ID 1000 (Application Error) entries referencing a crashing service.
B.System Event ID 7045 (A service was installed in the system) recorded once during the investigation window.
C.Sysmon Event ID 3 (NetworkConnect) entries showing repeated connections to the same external IP at regular intervals.
D.Security Event ID 4624 (An account was successfully logged on) with Logon Type 3 repeated every few minutes.
E.Sysmon Event ID 22 (DNSEvent) entries showing queries to the same domain at consistent time intervals.
AnswersC, E

Sysmon Event ID 3 records outbound network connections with process, source, destination, and port details. Repeated connections to the same external IP at consistent intervals are a hallmark of beaconing and directly evidence command-and-control traffic. Correlating the initiating process image and its hash strengthens the finding, making this one of the most direct artifacts for confirming periodic C2 behavior from the endpoint itself.

Why this answer

Beaconing is characterized by repeated, regular communication from a host to an external controller. Sysmon network-connect events and DNS query events both capture the timing, destination, and initiating process needed to confirm that pattern directly from the endpoint. Logon, application-crash, and service-install events may support the broader investigation but do not, by themselves, demonstrate periodic outbound C2 traffic.

Exam trap

The trap here is equating any recurring logon or service event with beaconing, when beaconing specifically requires repeated network or DNS activity tied to a process over time.

270
MCQmedium

You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?

A.windows.handles
B.windows.filescan
C.windows.privs
D.windows.dlllist
AnswerA

windows.handles lists the handles open in each process, including the object type, name, and access rights. For a file handle, it shows the full path and the granted access, which directly answers the question about the file's path and access type. This plugin is specifically designed to enumerate handles, making it the correct choice.

Why this answer

To find the full path and access type of a file handle, you need a plugin that enumerates handles per process. windows.handles provides exactly that, showing the object name (full path) and granted access for each handle. The other plugins focus on scanning file objects without process association, listing loaded DLLs, or displaying privileges, none of which directly answer the question about a specific handle.

Exam trap

The trap here is thinking that filescan will show which process has the file open, but filescan only lists file objects in memory without linking them to processes or showing access rights.

271
MCQmedium

An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?

A.The $MFT record's sequence number, because it increments each time the record is allocated to a new file
B.The $STANDARD_INFORMATION attribute timestamps, because they are updated on every file access
C.The volume's $Bitmap file, because it tracks the allocation status of every MFT record
D.The $FILE_NAME attribute timestamps, because they persist across record reuse
AnswerA

Each MFT entry contains a sequence number that is incremented every time the record is allocated to a different file. By comparing the sequence number observed at acquisition with earlier journal or log entries, an examiner can determine whether the record number has been reused and how many times.

Why this answer

The sequence number in an MFT file record is the key indicator of record reuse. It increases each time the record is allocated to a new file, so a higher sequence number than expected suggests the original file was deleted and the record was reassigned. Timestamps and $Bitmap do not preserve this allocation history.

Exam trap

The trap here is assuming that timestamp attributes alone can prove MFT record reuse, when only the sequence number records allocation changes.

272
MCQhard

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

A.To perform local file system encryption for data backup.
B.To download and execute a remote payload from a C2 server.
C.To monitor the system for unauthorized network connections.
D.To clear the Windows Event Logs to hide tracks.
AnswerB

The 'Net.WebClient' class is the standard, built-in way for PowerShell scripts to perform HTTP or HTTPS GET/POST requests to download remote data. In incident response, the presence of this class in a script is a strong indicator of a download-and-execute operation used by attackers to pull secondary malicious payloads.

Why this answer

The 'Net.WebClient' class in .NET is frequently used in PowerShell to download remote content. In a forensic context, it is a hallmark of download-and-execute malware. Attackers use this to fetch secondary payloads from C2 servers.

Identifying this class usage is critical for characterizing the scope of an attack, as it explains how the initial stub on the system was used to pull down more complex malicious tools.

Exam trap

Examinees sometimes misinterpret .NET class imports as benign software development activity instead of recognizing them as standard living-off-the-land download mechanisms.

273
Multi-Selectmedium

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Select 2 answers
A.The bit-depth of the monitor attached to the server
B.The footprint of the acquisition tool in RAM
C.The likelihood of a kernel panic during acquisition
D.The total capacity of the hard drive
E.The current time zone of the server
AnswersB, C

Any tool executed on a system modifies memory. Minimizing the size and scope of the memory acquisition tool is vital to ensure that the evidence is not corrupted or overwritten. Forensic analysts prioritize tools that have a small footprint to maintain the integrity of the captured image.

Why this answer

When performing memory acquisition, minimizing the footprint on the target system is essential to prevent the overwriting of volatile artifacts. Furthermore, the selection of the acquisition tool must account for potential security software interference that could cause a system crash or trigger alerts. These factors ensure that the resulting image is a forensically sound representation of the system state at the time of capture, avoiding unnecessary collateral damage to the evidence.

Exam trap

Candidates often prioritize the speed of acquisition or the amount of data captured, ignoring the critical risk of system instability or kernel panics that can destroy volatile memory evidence.

274
MCQhard

What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?

A.SI attributes are updated by the OS, while FN attributes are static.
B.Discrepancies often reveal timestomping attempts by attackers.
C.FN attributes are the only way to recover deleted files.
D.SI attributes are required for NTFS file permissions.
AnswerB

Attackers frequently modify the SI attributes to make malicious files appear older or consistent with other system files. Because they often overlook the FN attributes, comparing the two reveals the manipulation. This discrepancy is a standard forensic indicator used to identify hidden files that were created or modified maliciously.

Why this answer

The MFT contains two primary timestamps for each file: Standard Information (SI) and File Name (FN). Attackers often use 'timestomping' tools to modify the SI attributes to match legitimate files and hide their tracks. However, they frequently forget or are unable to modify the FN attributes, which are less accessible.

Discrepancies between these timestamps are a definitive indicator of anti-forensic activity that analysts use to uncover hidden malicious file creation times.

Exam trap

Candidates often assume that the MFT always reflects the true file creation time. They fail to realize that attackers frequently target the Standard Information attribute while neglecting the File Name attribute.

275
MCQmedium

An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?

A.Checking the file creation time in the MFT
B.Verifying the digital signature of the file
C.Searching for the process in the Shimcache
D.Viewing the process in Task Manager
AnswerB

A legitimate Windows system binary like svchost.exe will be signed by Microsoft. If the file in the AppData directory is unsigned, or if the signature is invalid, it is a definitive indicator that the file is not the genuine system binary, regardless of its filename or location.

Why this answer

Comparing the file's hash against known good values (e.g., from the National Software Reference Library) or checking digital signatures is standard forensic practice. Attackers often rename malicious binaries to match legitimate processes, but they cannot forge the cryptographic signature of a Microsoft-signed binary. If the file lacks a valid signature or has a mismatched hash, it confirms the binary is a malicious imposter intended to evade detection.

Exam trap

Analysts frequently rely only on file names, file sizes, or standard directory paths to validate system binaries, failing to notice that names like svchost.exe can be easily spoofed.

276
Multi-Selecthard

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Select 2 answers
A.windows.netscan
B.windows.vadinfo
C.windows.handles
D.windows.registry.hivelist
E.windows.malfind
AnswersB, E

windows.vadinfo dumps the virtual address descriptor tree for a process, showing each region's protection, commit type, and backing file. When combined with malfind, it lets you characterize the injected region by confirming whether it is private, executable, and fileless, which is essential for describing the injection in this scenario.

Why this answer

windows.malfind finds executable memory regions not backed by a file, which is the signature of injected code, while windows.vadinfo provides the virtual address descriptor details for those regions, including protection and commit type. Using them together lets the analyst detect the injection and then characterize it as private, executable, and fileless within the target process.

Exam trap

The trap here is selecting a network or handle plugin for injection analysis, when only memory-region plugins such as malfind and vadinfo reveal unbacked executable code.

277
MCQmedium

An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?

A.The Security event log, filtering for event ID 4698
B.The Task Scheduler operational event log (Microsoft-Windows-TaskScheduler/Operational.evtx)
C.The registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache
D.The Task Scheduler operational log, filtering for event ID 106
AnswerA

Event ID 4698 is generated when a scheduled task is created. It includes the task name, the user account that created it, and a timestamp. This directly answers the question of when the task was registered and who registered it, making it the most reliable artifact for this scenario.

Why this answer

Security event ID 4698 is the definitive artifact for scheduled task creation because it captures the task name, the creating user, and the timestamp. Other artifacts like the Task Scheduler operational log or registry keys may show the task exists or when it ran, but they do not reliably provide both the creator identity and the exact creation time, which are critical for attribution in an intrusion investigation.

Exam trap

The trap here is assuming the Task Scheduler operational log (event ID 106) provides user attribution for task creation, when it only records that a task was registered without identifying the account responsible.

278
MCQmedium

An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?

A.The $LogFile
B.The $Bitmap
C.The MFT record
D.The $Extend folder
AnswerC

Resident files store their data directly within the MFT record structure when the file size is smaller than the remaining space in the record. This avoids allocating a cluster, effectively keeping the file content embedded within the MFT itself, which forensic analysts must extract directly from the MFT entry.

Why this answer

In NTFS, small files are stored directly within the Master File Table (MFT) record as resident data. This is an optimization to save cluster space and reduce disk I/O. When the data attribute is resident, the content is part of the MFT entry itself, which is critical for investigators to understand when carving data, as standard file-based recovery tools might overlook these resident segments during deep analysis.

Exam trap

Candidates often assume the file must be corrupted or missing data, failing to recognize that small files can be stored 'resident' directly within the MFT record itself.

279
MCQmedium

During a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?

A.It removes sensitive PII from logs to ensure regulatory compliance.
B.It compresses log files, reducing storage costs for long-term retention.
C.It enables cross-platform correlation by providing a consistent event schema.
D.It automatically blocks malicious traffic detected within the log streams.
AnswerC

Normalization maps diverse log formats into a common format, allowing analysts to perform queries that span across different security devices. This consistency is critical for identifying lateral movement or multi-stage attacks where an actor touches multiple systems, ensuring that disparate events can be linked accurately during an incident investigation.

Why this answer

Log normalization transforms heterogeneous data from various vendors, formats, and sources into a standardized schema. This allows security tools to correlate events across the environment, such as matching a Windows Security log event to a Cisco firewall connection. Without normalization, analysts spend significant time manually parsing logs, which delays detection and increases the likelihood of missing subtle, multi-stage attack patterns that occur across disparate systems during an enterprise-wide security breach.

Exam trap

Candidates often think log normalization is about 'data compression' or 'storage optimization'. They miss the core security value, which is the ability to correlate disparate events into a single, cohesive attack timeline.

280
MCQmedium

Which technique is commonly used by attackers to maintain persistence on a Windows system that specifically targets the login process?

A.Adding a shortcut to the Startup folder.
B.Modifying the Windows registry Run keys.
C.Loading a malicious Security Support Provider (SSP).
D.Installing a malicious browser extension.
AnswerC

Loading a custom SSP via the registry allows the malicious DLL to be loaded into the LSASS process at boot. This provides the attacker with persistence that is integrated into the Windows authentication flow, allowing them to hook system functions and monitor credentials as they are entered by users.

Why this answer

The 'Authentication Packages' or 'SSP' (Security Support Provider) mechanism is a common target for persistence. By loading a malicious DLL as an SSP, the attacker ensures that their code is loaded into the Local Security Authority Subsystem Service (LSASS) process every time the system boots. This grants the attacker deep-level persistence and the ability to capture credentials as they are processed, making it a highly effective and stealthy technique for maintaining long-term access.

Exam trap

Candidates often confuse persistence with privilege escalation. While SSPs facilitate both, their specific role in the authentication chain makes them a primary target for stealthy, boot-time persistence.

281
MCQhard

During an investigation of an ext4 file system, an analyst runs `fls -r -m /` and `mactime` to build a body file. The analyst observes that many deleted files show a dtime in the body file, but the mactime timeline places those dtime entries at the time the file was deleted. A colleague claims that dtime in ext4 always represents the time the inode was last modified. Which statement correctly describes ext4 dtime behavior in this timeline context?

A.dtime is the inode deletion time and is populated when the inode is unlinked; mactime correctly maps it to the deletion event.
B.dtime is the inode modification time and is only populated for deleted files; mactime mislabels it as deletion time.
C.dtime is the time the inode was created and is preserved after deletion for timeline reconstruction.
D.dtime is the time the inode was last accessed and is updated whenever a deleted file is read during forensic acquisition.
AnswerA

In ext4, the dtime field records when the inode was deleted or unlinked. When `fls` extracts deleted entries and writes a body file, it includes dtime, and `mactime` renders it as a deletion event. This is why the timeline places dtime entries at the deletion moment, not at a modification time. The colleague's claim confuses dtime with mtime.

Why this answer

In ext4, the dtime field in the inode records when the file was deleted or unlinked. When `fls` extracts deleted inodes into a body file, it includes dtime, and `mactime` correctly renders it as a deletion event. Confusing dtime with mtime, atime, or crtime leads to timeline errors.

The colleague's claim is incorrect because mtime is a separate field.

Exam trap

The trap here is conflating ext4 dtime with mtime, when dtime specifically records deletion and is the only timestamp that mactime maps to a deletion event.

282
MCQhard

During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?

A.windows.dlllist
B.windows.cmdline
C.windows.pstree
D.windows.pslist
AnswerC

windows.pstree displays processes in a hierarchical tree based on parent-child relationships, making it easy to spot anomalies like a svchost.exe with an unexpected parent. It shows the PPID and the actual parent process, helping verify legitimacy. This plugin is ideal for investigating process spoofing by visualizing the process tree.

Why this answer

The windows.pstree plugin is designed to display processes in a tree structure, showing parent-child relationships. This makes it easy to spot a svchost.exe with an unusual parent, such as a non-system process, which is a common sign of process spoofing. Other plugins like pslist, cmdline, and dlllist do not provide this hierarchical view, making pstree the correct choice for verifying process legitimacy.

Exam trap

The trap here is relying on a flat process list that shows PPIDs but not the actual parent process, which can be misleading if the PPID is spoofed.

283
MCQmedium

A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?

A.The $STANDARD_INFORMATION timestamps were deliberately altered by a timestomping tool, while the $FILE_NAME timestamps reflect the actual file system activity.
B.The file was copied from an external NTFS volume, which preserved the original $STANDARD_INFORMATION timestamps but updated the $FILE_NAME timestamps.
C.The volume was formatted with a non-default cluster size, which causes $STANDARD_INFORMATION and $FILE_NAME timestamps to be updated independently.
D.The file system journal was replayed after an unclean shutdown, causing the $STANDARD_INFORMATION timestamps to roll back while the $FILE_NAME timestamps were left intact.
AnswerA

Timestomping utilities commonly modify the $STANDARD_INFORMATION timestamps because that is what Windows Explorer and many tools display, but they often overlook the $FILE_NAME attribute timestamps, which are updated by the file system during rename or creation events. The three-year-old values in $STANDARD_INFORMATION versus recent $FILE_NAME values strongly indicate deliberate manipulation of the $STANDARD_INFORMATION timestamps.

Why this answer

The $STANDARD_INFORMATION attribute is the primary target of timestomping tools because it is what most user-facing interfaces display. The $FILE_NAME attribute, which is indexed in the directory entry, is often left unchanged by such tools. A large discrepancy where $STANDARD_INFORMATION is backdated but $FILE_NAME reflects recent activity is a classic indicator of deliberate timestamp manipulation.

Exam trap

The trap here is assuming that any timestamp discrepancy between $STANDARD_INFORMATION and $FILE_NAME automatically proves timestomping, when legitimate operations such as file moves within a volume or certain backup restores can also produce differences.

284
Multi-Selectmedium

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

Select 3 answers
A.Thread Local Storage (TLS) pointers
B.Stack base and limit addresses
C.Exception handler chain head
D.Active process list pointer
E.Kernel-mode privilege level
AnswersA, B, C

The TEB contains the TLS array, which is used by threads to store and retrieve data that is unique to that specific thread. Malware often leverages TLS callbacks to execute code before the main entry point, making the inspection of this TEB structure vital for uncovering early-stage malicious execution.

Why this answer

The TEB is a user-mode structure that maintains thread-specific data, including the Thread Local Storage (TLS) array, exception handling chains, and the stack base/limit. Accessing the TEB is essential for forensic analysts because it helps decode how a specific thread executes, allows for the reconstruction of thread-local malware behavior, and provides insights into how the application manages its execution environment and exception handling.

Exam trap

Candidates often confuse the TEB with the PEB, mistakenly including process-wide information like environment variables or loader data, which are stored in the PEB rather than the thread-specific TEB structure.

285
MCQeasy

A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?

A.This is likely a legitimate software update mechanism, as many applications use scheduled tasks with hidden PowerShell for silent updates.
B.The task is likely a red herring because scheduled tasks cannot execute PowerShell scripts without administrative privileges.
C.The use of -EncodedCommand is a common obfuscation technique to hide malicious PowerShell code, and together with the hidden window and unusual creator, this strongly indicates persistence.
D.The scheduled task is benign because it runs every hour, which is a common interval for legitimate system maintenance tasks.
AnswerC

Attackers frequently use -EncodedCommand to obfuscate PowerShell payloads, and -WindowStyle Hidden to avoid detection. A scheduled task created by a non-administrative user that runs such a command hourly is a classic persistence mechanism. This finding warrants immediate investigation of the encoded command and the task's origin.

Why this answer

The combination of a scheduled task running PowerShell with an encoded command, a hidden window, and creation by a non-administrative user is a strong indicator of malicious persistence. Attackers use encoded commands to evade detection and scheduled tasks to maintain execution. This should be investigated by decoding the command and examining the task's XML for further clues.

Exam trap

The trap here is dismissing the finding because scheduled tasks are common, without recognizing that the specific flags and unusual creator account elevate it to a high-priority indicator of compromise.

286
MCQmedium

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

A.The memory segment is a standard heap allocation
B.The memory segment is a malicious injection
C.The memory segment is a legitimate shared library
D.The memory segment is part of the system kernel
AnswerB

The combination of Execute, Read, and Write permissions along with the lack of file-backing is a high-confidence indicator of injected code. This configuration allows a process to write a payload to memory and then immediately execute it, which is the standard methodology for process injection attacks.

Why this answer

The combination of PAGE_EXECUTE_READWRITE protection and the absence of an associated file (File: None) is a classic indicator of malicious code injection. Normal applications rarely allocate memory that is simultaneously writable and executable, as this violates standard security practices like Data Execution Prevention (DEP). The lack of a file-backing suggests the code resides entirely in memory, a common technique for fileless malware to avoid detection by traditional on-disk antivirus scanners.

Exam trap

Candidates often misinterpret PAGE_EXECUTE_READWRITE allocations as normal application behavior or routine caching, ignoring the strong malicious indicator of unbacked executable memory.

287
MCQeasy

An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?

A.The process is likely malicious persistence launched by cron from a non-standard, unmanaged path.
B.This is a legitimate kernel worker thread that cron spawned during routine maintenance.
C.The process is a normal systemd service that was forked by cron after a unit reload.
D.The process is a containerized workload placed in /tmp by the container runtime.
AnswerA

A root-owned executable in /tmp that is not tracked by the package manager and is parented by cron strongly suggests an attacker added a cron entry to execute a dropped binary. The name mimics a kernel worker to blend in, but kernel threads lack disk executables. The combination of location, ownership, parent, and missing package record makes a malicious interpretation the most defensible.

Why this answer

An unmanaged root-owned binary in /tmp executed by cron indicates an attacker added a scheduled job to launch a dropped payload. The kernel-thread-style name is a masquerade, since real kernel threads have no on-disk executable. Investigators should dump the crontab entries, hash the binary, and review /var/log/cron and auth logs for the insertion window.

Exam trap

The trap here is trusting the process name, because an attacker can name a binary to mimic a kernel worker while the executable path and package status reveal it is not legitimate.

288
MCQeasy

A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?

A.The NTFS $MFT, checking the timestamps of the updater.exe file in C:\Users\Public.
B.The SYSTEM registry hive, specifically the LastWrite time of the service key under HKLM\SYSTEM\CurrentControlSet\Services.
C.The Amcache.hve file, checking for the service binary path under the Root\InventoryApplicationFile key.
D.The Security event log, looking for event ID 4697 (A service was installed in the system).
AnswerB

The LastWrite time of a registry key indicates when the key was last modified. For a newly created service, the LastWrite time of its key in the SYSTEM hive will reflect the creation or last modification time. If this time correlates with the suspected infection window and the service binary is in a user-writable directory, it strongly suggests the service is malicious. Legitimate Windows services typically have older, consistent LastWrite times.

Why this answer

The LastWrite time of the service's registry key in the SYSTEM hive provides a direct timestamp for when the service configuration was last modified, which for a newly created service correlates with its installation. This artifact is stored locally and does not depend on audit policies. Other options either require non-default auditing, do not record service creation, or reflect file activity rather than service configuration.

Exam trap

The trap here is relying on event ID 4697 for service installation evidence, but that event is only generated when a non-default audit policy is enabled, so it may be absent.

289
MCQmedium

When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?

A.It stores the system's network configuration and IP addresses.
B.It tracks all executed application history.
C.It contains local user account data and password hashes.
D.It holds the logs for all system boot events.
AnswerC

The SAM hive is the repository for local user accounts. It stores account names, group membership, and password hashes. For forensic examiners, this is the primary source for identifying users on the system and potentially cracking passwords to determine the level of access an attacker gained.

Why this answer

The SAM (Security Accounts Manager) hive contains local user account information, including password hashes and group memberships. It is a critical target during forensic analysis for identifying user accounts, password history, and potential privilege escalation attempts. By extracting these hashes, analysts can perform offline cracking to reveal passwords, which is often necessary to understand the full extent of a compromised account's capability within the organization's network.

Exam trap

Candidates often confuse the SAM hive with the SYSTEM hive or security logs, failing to identify the SAM as the specific location for local user authentication data.

290
MCQeasy

An organization is responding to a ransomware incident. The attackers encrypted files on several servers and left a ransom note. Which immediate action should the incident response team take to preserve the most volatile evidence before shutting down the affected systems?

A.Interview system administrators about the ransomware note.
B.Collect volatile data such as memory and network connections.
C.Disconnect the servers from the network to prevent further spread.
D.Capture a forensic image of the disk drives.
AnswerB

Volatile data like memory contents, network connections, and running processes can be lost when a system is powered off. In a ransomware incident, memory may contain encryption keys, command-and-control connections, and other actionable intelligence. Collecting this data first follows the order of volatility and ensures critical evidence is preserved before any shutdown or disk imaging.

Why this answer

The order of volatility dictates that the most volatile evidence, such as memory and network connections, should be collected first. In a ransomware incident, memory can contain encryption keys and indicators of compromise that are crucial for response and recovery. Disk imaging and containment actions can be performed afterward without losing this critical data.

Interviews are non-technical and can be done at any time.

Exam trap

The trap here is prioritizing containment or disk imaging over volatile data collection, which can result in the permanent loss of memory-resident evidence like encryption keys.

291
MCQmedium

During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?

A.SRUM (System Resource Usage Monitor) database
B.Registry key LastWrite time under HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>
C.Amcache.hve inventory entry for the service executable
D.Prefetch file for the service executable (e.g., SERVICENAME.EXE-XXXXXXXX.pf)
AnswerB

The Services registry key stores configuration for each installed service. When a service is created or modified, the LastWrite time of its subkey under CurrentControlSet\Services is updated. This timestamp persists even if the executable is deleted and event logs are cleared, providing a reliable forensic indicator of when the service was installed or last altered. Analysts can correlate this with other artifacts to confirm the installation time.

Why this answer

The Services registry key maintains configuration data for each service, and its LastWrite time updates upon creation or modification. This artifact survives executable deletion and log clearing, offering a reliable timestamp for service installation. Other artifacts like SRUM, Prefetch, or Amcache provide execution or resource usage context but not the specific service registration time.

Exam trap

The trap here is assuming that execution artifacts like Prefetch or Amcache can pinpoint service installation, when they actually indicate execution or file inventory.

292
MCQhard

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?

A.The tool will recover only the first 800 bytes from the data runs, which are partially resident.
B.The tool will successfully recover the file content because the data is stored in the MFT record.
C.The tool will fail to recover the file content because it does not parse the resident data within the MFT record.
D.The tool will recover the file content from the $ATTRIBUTE_LIST if the resident data overflows the MFT record.
AnswerC

Resident $DATA attributes store the file content directly within the MFT record, not in separate clusters. A tool that only reads data runs is designed for non-resident attributes and will not extract resident data. Thus, the recovery attempt will fail because the tool does not parse the resident data. The content remains in the MFT record but is inaccessible to this tool.

Why this answer

Resident $DATA attributes store file content directly within the MFT record, not in separate clusters. A tool that only reads data runs is designed for non-resident attributes and will not extract resident data. Therefore, the recovery attempt will fail because the tool does not parse the resident data.

The content remains in the MFT record but is inaccessible to this tool.

Exam trap

The trap here is assuming that all file data is stored in data runs, ignoring the fact that small files can have resident $DATA attributes where content is embedded in the MFT record.

Page 3

Page 4 of 4

All pages