GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?
⚠ Common exam trap
The trap here is relying on execution artifacts like Prefetch or SRUM to prove legitimacy, when only signature verification can confirm the binary's authenticity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The digital signature of the svchost.exe file
Verifying the digital signature of the executable is the most direct way to confirm whether svchost.exe is the legitimate Microsoft binary. A valid signature from Microsoft indicates the file is authentic and unmodified, while an invalid or missing signature suggests masquerading. Other artifacts like Prefetch, $MFT, and SRUM provide contextual information but do not verify integrity and origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SRUM database entry for svchost.exe
Why it's wrong here
The SRUM database tracks resource usage and network data per process, but it does not validate the authenticity of the executable. It can show that svchost.exe consumed resources or communicated over the network, but it cannot confirm whether the binary is the legitimate Microsoft version.
- ✗
The $MFT record for the svchost.exe file
Why it's wrong here
The $MFT record provides file metadata such as timestamps and size, but it does not contain digital signature information or verify the file's origin. It can help confirm the file's location and creation time, but it cannot prove the binary is the legitimate Microsoft svchost.exe.
- ✓
The digital signature of the svchost.exe file
Why this is correct
Checking the digital signature verifies whether the executable is signed by Microsoft and has not been tampered with. A legitimate svchost.exe should be signed by Microsoft and reside in System32. If the signature is invalid or missing, it indicates a masquerading attempt, directly addressing the analyst's need to verify integrity and origin.
- ✗
The Prefetch file for svchost.exe
Why it's wrong here
Prefetch files record execution counts and file paths but do not verify the digital signature or origin of the executable. They can show that svchost.exe ran, but they cannot distinguish a legitimate Microsoft binary from a malicious one placed in a different directory.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.