GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?
⚠ Common exam trap
Candidates often misinterpret internal non-routable subnet traffic as benign local communication, ignoring the significance of Logon Type 3 followed immediately by Event ID 4672.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An adversary performed lateral movement using stolen administrative credentials over the network to access administrative shares.
This specific sequence indicates a network logon successfully authenticating an administrative user, frequently observed during lateral movement via SMB or PsExec. Understanding this pattern allows analysts to differentiate authorized administrative maintenance from credential-based attacks, mapping directly to attacker tactics in enterprise environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An interactive user logged into the local console, triggering default privilege escalation assignments.
Why it's wrong here
Logon Type 3 is a network logon, not an interactive console logon (Type 2), so this interpretation contradicts the event data. It is tempting because 4672 does follow successful logons, but Type 2 would be correct for a user physically at the machine, not a remote subnet source.
- ✗
A scheduled batch job executed locally using stored credentials without generating network authentication traffic.
Why it's wrong here
Batch jobs utilize Logon Type 4 instead of Logon Type 3. Because network logons require remote connectivity indicators, batch tasks restricted to local execution do not produce the network source IP fields typically logged in Type 3 events.
- ✓
An adversary performed lateral movement using stolen administrative credentials over the network to access administrative shares.
Why this is correct
Logon Type 3 signifies a network authentication session, and Event ID 4672 explicitly records the assignment of special privileges to new logon sessions. Attackers routinely leverage network shares and administrative credentials to pivot across internal enterprise endpoints seamlessly.
- ✗
A service account automatically restarted following a system crash, initiating local service control manager requests.
Why it's wrong here
Service restarts produce Logon Type 5 (service) events, not Type 3 network logons, and 4672 follows interactive or network authentication rather than crash recovery. It is tempting because service accounts do generate 4672, but Type 5 would be correct for a service start, not a remote network source.
Visual reference
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.