GCFA Windows Artifact Analysis Practice Question
An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)
⚠ Common exam trap
The trap here is focusing on generic network logon events or Amcache entries, which are not specific to PsExec, instead of the distinctive service installation and Prefetch artifacts that PsExec creates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System event log for Event ID 7045 (service installation)
PsExec usage on a target system leaves two key artifacts: the installation of the PSEXESVC service, recorded in the System event log as Event ID 7045, and the execution of PSEXESVC.exe, which generates a Prefetch file. These directly indicate PsExec activity. Other artifacts like network logons or Amcache entries are less specific and may be caused by other activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
System event log for Event ID 7045 (service installation)
Why this is correct
PsExec installs a temporary service named PSEXESVC on the target system. The installation of this service is recorded in the System event log with Event ID 7045, which includes the service name, image path, and service type. This provides strong evidence that PsExec was used, especially if the service name matches PSEXESVC.
- ✓
Prefetch files for PSEXESVC.exe
Why this is correct
When PsExec is used to execute a command remotely, it installs and runs a service executable named PSEXESVC.exe on the target system. The execution of this file will generate a Prefetch file (PSEXESVC.EXE-*.pf) if Prefetch is enabled. The Prefetch file records the last execution time and run count, providing direct evidence that PsExec was used on the system.
- ✗
Amcache.hve for entries related to PsExec.exe
Why it's wrong here
Amcache.hve records metadata about executables that have run on the system, but it does not specifically record PsExec usage on the target. Amcache is more useful for tracking the presence of files, not the execution of remote commands. Additionally, PsExec.exe is typically run on the attacker's system, not the target, so Amcache on the target would not show it.
- ✗
SRUM database for network connections by PsExec.exe
Why it's wrong here
The SRUM database tracks resource usage by applications, including network data, but it does not attribute network connections to specific remote commands like PsExec. PsExec does not run as a persistent process on the target; it installs a service. SRUM may not capture the short-lived service activity, making it unreliable for corroborating PsExec usage.
- ✗
Security event log for Event ID 4624 with Logon Type 3
Why it's wrong here
Event ID 4624 with Logon Type 3 indicates a network logon, which is common for many remote access methods, including legitimate file shares. While PsExec may generate such logons, they are not specific to PsExec and can be caused by numerous other activities. Therefore, this artifact alone is not a reliable corroboration of PsExec usage.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.