GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?
⚠ Common exam trap
The trap here is assuming that any cmd.exe to powershell.exe chain is malicious, but it can be benign; however, the event itself only describes the relationship, not intent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A process named cmd.exe spawned a PowerShell process, which could indicate scripted or malicious activity.
Event ID 4688 includes the creator process name and new process name. In this case, cmd.exe created powershell.exe, indicating a parent-child relationship that is often seen in malicious scripts, such as those that use PowerShell for download or execution. While it could be benign, it is a suspicious pattern that should be investigated further. The other options either assume benign user action, introduce unsupported context, or reverse the relationship.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A process named cmd.exe spawned a PowerShell process, which could indicate scripted or malicious activity.
Why this is correct
Event ID 4688 records the creation of a new process and includes the creator process name. Here, cmd.exe is the creator of powershell.exe. This parent-child relationship is a common technique in malicious scripts, such as those used in fileless attacks or lateral movement. It does not prove maliciousness but is a suspicious pattern that warrants further investigation. This option accurately describes the event.
- ✗
The system automatically started a PowerShell process as part of a scheduled task.
Why it's wrong here
The event does not indicate a scheduled task. Scheduled task creation would generate different events, such as Event ID 4698 or Task Scheduler operational logs. While a scheduled task could ultimately spawn cmd.exe that then launches PowerShell, the event itself only shows the immediate parent. This option adds context not present in the event, making it incorrect.
- ✗
PowerShell was used to execute a command that created cmd.exe.
Why it's wrong here
The event shows the opposite relationship: cmd.exe created powershell.exe. The 'Creator Process Name' is cmd.exe and the 'New Process Name' is powershell.exe. Therefore, this option reverses the parent-child relationship and is factually incorrect based on the event details.
- ✗
A user manually opened a command prompt and then launched PowerShell.
Why it's wrong here
While this is a possible benign scenario, the event alone does not confirm manual user action. The event only records that cmd.exe created powershell.exe. It could be part of a script or malicious chain. This option assumes benign user behavior without evidence, which is not supported by the event data alone. Therefore, it is not the best description.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.