Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An attacker is using a living-off-the-land (LotL) technique to execute commands on a Linux server. Which log source is most likely to reveal the command-line arguments used?

⚠ Common exam trap

Candidates frequently select Bash history, forgetting it is easily cleared or disabled by attackers. Auditd is the system-level standard that captures execution regardless of user-space shell configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Linux Audit Framework (auditd).

Linux auditd is the most robust tool for capturing process execution details. By configuring auditd to watch the 'execve' system call, responders can log every command executed, including its arguments, by every user on the system. This is invaluable during an incident because LotL techniques often use standard, trusted binaries to perform malicious acts, and command-line arguments are the only evidence distinguishing legitimate administrative use from an attacker's malicious actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog (/var/log/syslog).

    Why it's wrong here

    Syslog typically records service-level status messages and application events. It rarely captures the full command-line arguments of processes being executed by users. Relying on syslog for forensic investigation of command execution often leads to significant gaps in visibility, especially when attackers use standard binaries to perform their malicious tasks.

  • ✓

    Linux Audit Framework (auditd).

    Why this is correct

    The Linux Audit Framework is designed to record system calls, including the 'execve' system call. This allows it to capture the exact command-line arguments passed to any binary, providing a detailed record of what an attacker did. This level of detail is essential for identifying LotL activity on Linux hosts.

  • ✗

    Apache Access Logs.

    Why it's wrong here

    Apache access logs record incoming web requests, such as the page requested and the IP address. They do not record the command-line activity occurring on the underlying OS. While they might show a trigger for a web shell, they won't show the secondary commands an attacker runs once they have access.

  • ✗

    X11 Display Logs.

    Why it's wrong here

    X11 logs pertain to the graphical windowing system on Linux. They do not capture shell-based command-line execution or the arguments used by processes running in the background. Investigating these logs would be completely irrelevant for detecting command-line techniques used by an attacker in a server-side environment or via SSH.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.