GCFA Enterprise Environment Incident Response Practice Question
An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to exfiltrate messages. The team has identified the compromised account and wants to determine the full scope of mailbox access and rule creation across the tenant. Which single action should the responder take to obtain the authoritative audit record of these activities?
⚠ Common exam trap
The trap here is assuming that message trace or Microsoft Entra ID sign-in logs contain mailbox rule creation and access details, when those events are only recorded in the Unified Audit Log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Export the Unified Audit Log from the Microsoft 365 compliance center and filter for mailbox rule and access events
The Unified Audit Log is the authoritative tenant-wide record for mailbox access and rule creation in Microsoft 365. It captures events like New-InboxRule and MailItemsAccessed, allowing the responder to determine the full scope of adversary activity. Message trace, client logs, and Microsoft Entra ID sign-in logs provide complementary but incomplete views and do not record the mailbox-level actions needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a message trace in the Exchange admin center for the past 30 days
Why it's wrong here
Message trace shows the delivery path of messages through the mail system, but it does not record mailbox rule creation or mailbox access events. It is useful for tracking message flow, yet it cannot reveal who accessed the mailbox or what forwarding rules were created, so it is insufficient for scope determination.
- ✗
Inspect the Microsoft Entra ID sign-in logs for the compromised account
Why it's wrong here
Microsoft Entra ID sign-in logs show authentication events and some risk detections, but they do not contain mailbox-level actions such as rule creation or message access. They can complement the investigation by showing logon locations, but they do not provide the authoritative mailbox audit record required here.
- ✓
Export the Unified Audit Log from the Microsoft 365 compliance center and filter for mailbox rule and access events
Why this is correct
The Unified Audit Log in the Microsoft 365 compliance center records mailbox access, rule creation, and other tenant activities across services. Exporting and filtering it for events such as New-InboxRule and MailItemsAccessed provides the authoritative, tenant-wide record needed to determine the full scope of the adversary's mailbox actions.
- ✗
Review the mailbox owner's Outlook client logs on their workstation
Why it's wrong here
Client-side logs on the user's workstation may show local Outlook activity, but they do not provide authoritative tenant-wide audit records of mailbox access or rule creation. An adversary using a different client or API would not appear in these logs, so they cannot establish the full scope of the incident.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.