GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?
⚠ Common exam trap
Analysts frequently rely only on file names, file sizes, or standard directory paths to validate system binaries, failing to notice that names like svchost.exe can be easily spoofed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verifying the digital signature of the file
Comparing the file's hash against known good values (e.g., from the National Software Reference Library) or checking digital signatures is standard forensic practice. Attackers often rename malicious binaries to match legitimate processes, but they cannot forge the cryptographic signature of a Microsoft-signed binary. If the file lacks a valid signature or has a mismatched hash, it confirms the binary is a malicious imposter intended to evade detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Checking the file creation time in the MFT
Why it's wrong here
File timestamps are easily manipulated by attackers using 'timestomping' techniques. Relying on MFT timestamps to determine the authenticity of a file is unreliable, as an attacker can easily copy the timestamps from another system file to make the malicious binary appear as though it has been present for years.
- ✓
Verifying the digital signature of the file
Why this is correct
A legitimate Windows system binary like svchost.exe will be signed by Microsoft. If the file in the AppData directory is unsigned, or if the signature is invalid, it is a definitive indicator that the file is not the genuine system binary, regardless of its filename or location.
- ✗
Searching for the process in the Shimcache
Why it's wrong here
The Shimcache records that a file was executed, but it does not verify the file's integrity or authenticity. An attacker can run a malicious file that is masquerading as svchost.exe, and the Shimcache will simply record that a file with that name was executed, providing no verification of its origin.
- ✗
Viewing the process in Task Manager
Why it's wrong here
Task Manager provides a basic view of running processes but does not verify the authenticity or the cryptographic signature of the underlying binary. An attacker can easily hide their malicious process in Task Manager, and the information provided there is insufficient for forensic identification of a masquerading binary.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.