Courseiva
Windows Artifact Analysis →mediumMultiple Choice

GCFA Windows Artifact Analysis Practice Question

An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?

⚠ Common exam trap

The trap here is assuming the Task Scheduler operational log (event ID 106) provides user attribution for task creation, when it only records that a task was registered without identifying the account responsible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Security event log, filtering for event ID 4698

Security event ID 4698 is the definitive artifact for scheduled task creation because it captures the task name, the creating user, and the timestamp. Other artifacts like the Task Scheduler operational log or registry keys may show the task exists or when it ran, but they do not reliably provide both the creator identity and the exact creation time, which are critical for attribution in an intrusion investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Security event log, filtering for event ID 4698

    Why this is correct

    Event ID 4698 is generated when a scheduled task is created. It includes the task name, the user account that created it, and a timestamp. This directly answers the question of when the task was registered and who registered it, making it the most reliable artifact for this scenario.

  • ✗

    The Task Scheduler operational event log (Microsoft-Windows-TaskScheduler/Operational.evtx)

    Why it's wrong here

    The Task Scheduler operational log records events such as task start, completion, and action execution, but it does not reliably capture the initial creation time or the user who registered the task. It is useful for execution history, not for proving when and by whom the task was created, which is the specific requirement here.

  • ✗

    The registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache

    Why it's wrong here

    The TaskCache registry key stores task definitions and some metadata, but it does not record the user who created the task or the precise creation time in a forensically reliable way. It may show the task exists, but not the attribution or exact registration timestamp needed.

  • ✗

    The Task Scheduler operational log, filtering for event ID 106

    Why it's wrong here

    Event ID 106 in the Task Scheduler operational log indicates that a task was registered, but it does not include the user account that performed the registration. It provides a timestamp but lacks the identity information needed to attribute the creation to a specific user, so it is insufficient for the full requirement.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.