GCFA Enterprise Environment Incident Response Practice Question
An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any log mentioning account activity is sufficient, while overlooking that the SAM hive provides persistent account data even if event logs are cleared.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SAM registry hive
The Security event log records account creation (4720) and logon events (4624), providing a timeline of the attacker's actions. The SAM registry hive stores the local account database, including the new account's details, and can be analyzed even if logs are cleared. Together, they offer direct evidence of the new account and its use, which is critical for understanding the persistence mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application event log (Event ID 1000)
Why it's wrong here
Event ID 1000 in the Application log typically indicates an application error or crash. It is not related to user account creation or logon activity. This log would not contain evidence of the attacker's actions in this scenario.
- ✓
SAM registry hive
Why this is correct
The SAM registry hive stores local user account information, including usernames, password hashes, and account creation dates. Analyzing the SAM hive can reveal the presence of the newly created local account, even if event logs have been cleared. It provides a persistent record of the account's existence and attributes.
- ✓
Security event log (Event ID 4720 and 4624)
Why this is correct
Event ID 4720 is generated when a user account is created, and Event ID 4624 is generated when a logon is successful. By examining the Security event log, the responder can see the creation of the new account and subsequent logons using that account. This directly addresses the need to identify the new account and its logon activity.
- ✗
System event log (Event ID 7045)
Why it's wrong here
Event ID 7045 indicates a new service was installed. While attackers sometimes create services for persistence, the scenario specifies a new local user account, not a service. Therefore, the System event log is not the best source for this specific evidence.
- ✗
Prefetch files
Why it's wrong here
Prefetch files record the execution of applications to improve performance. They might show that tools like 'net.exe' were used to create a user, but they do not directly show the account creation or logon events. They are less direct than Security event logs or the SAM hive for this purpose.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.