Courseiva
Windows Artifact Analysis →mediumMultiple Choice

GCFA Windows Artifact Analysis Practice Question

An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?

⚠ Common exam trap

Candidates incorrectly believe the Shimcache provides a precise execution timestamp, leading them to misinterpret the 'Last Modified' file metadata as the moment the malicious file was run.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It tracks file path and last modification time for potential application compatibility.

The Shimcache, or AppCompatCache, tracks file metadata to ensure application compatibility. Crucially, it tracks file paths and last modified times but does not natively record the exact execution timestamp of an application. It is primarily used to identify files that were present on the system and potentially executed, serving as a critical indicator of software presence during an investigation into lateral movement or malware persistence on a Windows endpoint.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It records the exact UTC execution time for all files in the SYSTEM hive.

    Why it's wrong here

    Shimcache entries include file path and last modification time, but they do not store the specific time a file was executed. Relying on this for execution timing leads to inaccurate timelines, as the artifact tracks file presence and compatibility rather than discrete process launch events.

  • ✗

    Entries are only populated when the UserAssist key is enabled in the registry.

    Why it's wrong here

    Shimcache is a standalone component of the SYSTEM registry hive and functions independently of UserAssist. UserAssist tracks GUI-based application usage per user profile, whereas Shimcache tracks system-wide application compatibility data, making them distinct artifacts with different forensic purposes and locations within the Windows Registry structure.

  • ✓

    It tracks file path and last modification time for potential application compatibility.

    Why this is correct

    Shimcache stores the file path and the last modified time of the executable. This helps the OS determine if a file is compatible. For forensics, this artifact is essential for identifying executable files that existed on the system, even if those files were subsequently deleted by an attacker.

  • ✗

    It is stored within the NTUSER.DAT hive for each individual user profile.

    Why it's wrong here

    The Shimcache data is stored in the SYSTEM hive, specifically under the CurrentControlSet\Control\Session Manager\AppCompatCache key. It is a system-wide artifact, not a user-specific one. Misattributing this to NTUSER.DAT causes significant confusion during scoping, as you would be unable to locate the necessary data for analysis.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.