GCFA Windows Artifact Analysis Practice Question
An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?
⚠ Common exam trap
The trap here is assuming that any execution artifact, such as Prefetch or Amcache, provides process creation timestamps and parent-child links, when only Sysmon Event ID 1 does so with the needed fidelity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sysmon Event ID 1 (Process Creation) in the Windows Event Log
Sysmon Event ID 1 provides the most granular and reliable data for process creation, including exact timestamps and parent-child relationships. Other artifacts like Prefetch, Amcache, and UserAssist offer execution evidence but lack the precision and relationship details needed to reconstruct the sequence of events accurately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prefetch files in C:\Windows\Prefetch
Why it's wrong here
Prefetch files record execution counts and last-run times, but they do not capture the exact process creation timestamp or parent-child relationships for every execution. They are also limited to executables that have prefetching enabled, and the timestamps are often coarse. In this scenario, the analyst needs precise creation time and lineage, which Prefetch alone cannot provide.
- ✗
UserAssist registry keys
Why it's wrong here
UserAssist keys record GUI-based program executions by a specific user, storing a last-execution time and run count. They do not capture the exact creation time of a process or its parent-child relationship, and they only cover programs launched via Explorer. This makes them unsuitable for determining precise process creation timing or lineage.
- ✗
Amcache.hve registry hive
Why it's wrong here
Amcache.hve primarily tracks metadata about executed binaries, such as file paths and SHA-1 hashes, but it does not record precise process creation times or parent-child relationships. It is useful for identifying what ran on a system, but not for establishing exact execution timelines or process lineage. Therefore, it is insufficient for the analyst's specific need.
- ✓
Sysmon Event ID 1 (Process Creation) in the Windows Event Log
Why this is correct
Sysmon Event ID 1 logs detailed process creation events, including the exact UTC timestamp, process GUID, image path, command line, and parent process ID. This directly answers when the process started and its parent-child relationship. If Sysmon was installed and configured, this is the most precise and reliable artifact for the scenario.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.