GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?
⚠ Common exam trap
Candidates frequently jump to conclusions by analyzing DNS queries in isolation without correlating them with actual socket ownership or local process execution on the host.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Correlate the DNS query timestamps with socket ownership via netstat or EDR telemetry.
Isolating the process behavior through network connection correlation allows the analyst to map the C2 traffic to a specific binary. Identifying the parent process and local socket ownership is essential to distinguish between legitimate background tasks and automated beaconing activity. This helps narrow the scope of the investigation by confirming the persistence mechanism and the specific threat actor communication pattern associated with the compromised host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a full disk imaging of the host immediately.
Why it's wrong here
Full disk imaging is a standard preservation step but does not provide immediate insight into the current process-to-network mapping. The analyst needs volatile data to confirm the active C2 beaconing status before the malware potentially detects the forensic acquisition process and terminates the malicious connection.
- ✗
Execute an immediate reboot of the affected system.
Why it's wrong here
Rebooting the system destroys critical volatile evidence stored in memory, including active connections, running process trees, and injected code. This action is counterproductive for forensic analysis, as it effectively clears the evidence required to identify the root cause of the unauthorized DNS activity and malware persistence.
- ✓
Correlate the DNS query timestamps with socket ownership via netstat or EDR telemetry.
Why this is correct
Mapping process IDs to remote network connections provides definitive proof of which executable is responsible for the beaconing. By comparing the process creation time and the socket initiation time, the analyst can identify the specific binary responsible for the traffic, which is a foundational step in host-based incident response.
- ✗
Flush the local DNS resolver cache on the host.
Why it's wrong here
Flushing the cache only removes the current resolution results and does not stop the underlying process from initiating new queries. This action fails to identify the source of the beaconing and may alert the attacker that their activity has been detected, potentially leading to defensive counter-measures.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.