GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)
⚠ Common exam trap
The trap here is reaching for execution-history artifacts like Prefetch or Amcache, which prove a binary ran but say nothing about who opened LSASS memory or with what access mask.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A memory image search for the 'sekurlsa' module strings and Mimikatz driver artifacts in non-paged pool.
Establishing unauthorized LSASS access requires artifacts that either record the access event itself or demonstrate the presence of credential-dumping tooling. Sysmon process-access events capture the target process, requesting image, and granted access mask, while memory-resident strings and driver artifacts left by frameworks like Mimikatz show the tooling was loaded. Together they provide both the access event and the capability evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prefetch files showing that the Windows Credential Manager UI was launched by the user.
Why it's wrong here
Prefetch records execution of a specific binary with load statistics but has no visibility into handle requests or memory reads against another process. Launching the Credential Manager UI is a normal user action that does not touch LSASS memory in the way a dumping tool does, so it does not indicate unauthorized access to the LSASS process space.
- ✓
A memory image search for the 'sekurlsa' module strings and Mimikatz driver artifacts in non-paged pool.
Why this is correct
Residues of credential-dumping frameworks such as the sekurlsa module strings or the Mimikatz kernel driver can persist in memory after execution and are recoverable from a full memory capture. Finding them demonstrates the tooling was present and loaded on the host, which corroborates that LSASS memory was targeted even if the dumping process has already exited.
- ✗
Security Event ID 4688 process creation records showing the parent image of every long-running service.
Why it's wrong here
4688 records process creation and parent image, which is useful for building a process tree, but it does not record handle requests or access masks against a target process. It cannot by itself show whether lsass.exe memory was read, so it is a supporting artifact at best and not a direct indicator of unauthorized LSASS access.
- ✓
Sysmon Event ID 10 records showing a process opening lsass.exe with GrantedAccess 0x1010 or 0x1410.
Why this is correct
Sysmon Event ID 10 logs process access with the requested access mask and target process, so an entry showing lsass.exe as the target with the specific read-memory access rights associated with credential dumping tools directly evidences unauthorized access to LSASS memory. This is one of the most reliable high-fidelity indicators because legitimate processes rarely request those exact masks against lsass.
- ✗
Amcache entries listing hashes of binaries installed under 'Program Files' on the host.
Why it's wrong here
Amcache tracks execution and installation metadata for binaries, which helps identify tooling that ran from disk, but it does not record inter-process access or target a specific process's memory. It cannot establish that lsass.exe was opened with credential-dumping access masks, so it is not a direct artifact for this question.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.