Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?

⚠ Common exam trap

Candidates frequently try to read encoded PowerShell command strings manually without decoding the Base64 payload first, wasting time on obfuscated syntax.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a base64 decoder to convert the command string to plaintext.

Base64 encoded PowerShell commands are a common tactic to bypass signature-based detection. The analyst must extract the encoded string, decode it using standard utilities like CyberChef or PowerShell itself, and then perform static analysis on the resulting script. This process is vital to understand the attacker's intent, such as identifying hidden C2 downloaders, persistence scripts, or data collection commands that were otherwise obscured from basic text-based log searches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the script directly in a production environment to see its effect.

    Why it's wrong here

    Executing suspicious scripts in production is dangerous and violates forensic integrity. It risks activating malware, causing system instability, or triggering unwanted side effects. Analysts must always use sandboxed environments or static analysis techniques to safely evaluate the content of scripts before determining their full functional impact.

  • ✓

    Use a base64 decoder to convert the command string to plaintext.

    Why this is correct

    Decoding the base64 string reveals the original PowerShell code, which is essential for understanding the intended actions. This allows the analyst to identify malicious logic, such as network connections or file system changes, that the attacker was attempting to hide from traditional security monitoring tools and administrative logs.

  • ✗

    Search for the command in the Windows Update history.

    Why it's wrong here

    PowerShell command execution is not tracked or stored in Windows Update history logs. This approach is completely ineffective for retrieving the content of executed scripts. Analysts should focus on PowerShell Script Block Logging (Event ID 4104) to capture the de-obfuscated code executed by the engine.

  • ✗

    Check the local BIOS/UEFI logs for the command execution.

    Why it's wrong here

    BIOS and UEFI logs store hardware-level events, not operating system application activity. PowerShell command history is not reflected in these firmware logs. Searching here would yield no relevant data, as the activity occurs exclusively within the user-mode execution environment managed by the Windows operating system.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.