GCFA Windows Artifact Analysis Practice Question
An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)
⚠ Common exam trap
The trap here is assuming that network connection logs or execution artifacts can prove file share access, when only specific security events like 4624 Type 3 and 5140 capture the account and share details.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security Event ID 4624 with Logon Type 3
Security Event ID 4624 with Logon Type 3 and Event ID 5140 both directly record network logons and share access, respectively. They provide the account, timestamp, and share details needed to prove a user accessed a remote share. The other artifacts lack the specificity to directly evidence this activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security Event ID 4624 with Logon Type 3
Why this is correct
Security Event ID 4624 with Logon Type 3 indicates a network logon, which occurs when a user accesses a remote share. It records the account name, logon time, and source network address. This directly evidences remote file share access, making it a primary artifact for the scenario.
- ✗
UserAssist registry keys
Why it's wrong here
UserAssist keys record GUI-based program executions by a user, such as launching Explorer. They do not log network share access or the remote paths accessed. They might show that Explorer was opened, but not what was accessed remotely. Thus, they are not direct evidence of remote file share activity.
- ✗
Prefetch files for the remote access client
Why it's wrong here
Prefetch files show that an application like Explorer or a command-line tool was executed, but they do not record the target of a network share access or the user account used. They are too generic to prove remote file share access. They might corroborate that a tool was run, but not the specific activity.
- ✓
Security Event ID 5140 for a network share object
Why this is correct
Security Event ID 5140 is logged when a network share object is accessed. It includes the share name, the account that accessed it, and the source address. This event is specifically generated for file share access, providing direct evidence of the activity in question. It is often enabled with object access auditing.
- ✗
Sysmon Event ID 3 (Network Connection)
Why it's wrong here
Sysmon Event ID 3 logs network connections made by processes, including source and destination IP addresses and ports. While it can show that a process connected to a remote system, it does not directly indicate file share access or the user account involved. It lacks the specificity of logon events for identifying share access.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.