Courseiva
Windows Artifact Analysis →mediumMultiple Select

GCFA Windows Artifact Analysis Practice Question

An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)

⚠ Common exam trap

The trap here is focusing on generic network logon events or Amcache entries, which are not specific to PsExec, instead of the distinctive service installation and Prefetch artifacts that PsExec creates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

System event log for Event ID 7045 (service installation)

PsExec usage on a target system leaves two key artifacts: the installation of the PSEXESVC service, recorded in the System event log as Event ID 7045, and the execution of PSEXESVC.exe, which generates a Prefetch file. These directly indicate PsExec activity. Other artifacts like network logons or Amcache entries are less specific and may be caused by other activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    System event log for Event ID 7045 (service installation)

    Why this is correct

    PsExec installs a temporary service named PSEXESVC on the target system. The installation of this service is recorded in the System event log with Event ID 7045, which includes the service name, image path, and service type. This provides strong evidence that PsExec was used, especially if the service name matches PSEXESVC.

  • ✓

    Prefetch files for PSEXESVC.exe

    Why this is correct

    When PsExec is used to execute a command remotely, it installs and runs a service executable named PSEXESVC.exe on the target system. The execution of this file will generate a Prefetch file (PSEXESVC.EXE-*.pf) if Prefetch is enabled. The Prefetch file records the last execution time and run count, providing direct evidence that PsExec was used on the system.

  • ✗

    Amcache.hve for entries related to PsExec.exe

    Why it's wrong here

    Amcache.hve records metadata about executables that have run on the system, but it does not specifically record PsExec usage on the target. Amcache is more useful for tracking the presence of files, not the execution of remote commands. Additionally, PsExec.exe is typically run on the attacker's system, not the target, so Amcache on the target would not show it.

  • ✗

    SRUM database for network connections by PsExec.exe

    Why it's wrong here

    The SRUM database tracks resource usage by applications, including network data, but it does not attribute network connections to specific remote commands like PsExec. PsExec does not run as a persistent process on the target; it installs a service. SRUM may not capture the short-lived service activity, making it unreliable for corroborating PsExec usage.

  • ✗

    Security event log for Event ID 4624 with Logon Type 3

    Why it's wrong here

    Event ID 4624 with Logon Type 3 indicates a network logon, which is common for many remote access methods, including legitimate file shares. While PsExec may generate such logons, they are not specific to PsExec and can be caused by numerous other activities. Therefore, this artifact alone is not a reliable corroboration of PsExec usage.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.