GCFA Windows Artifact Analysis Practice Question
An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?
⚠ Common exam trap
The trap here is assuming that any log showing PowerShell execution will contain the command details, when in fact only the PowerShell Operational log with script block logging enabled provides that level of detail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PowerShell Operational Event Log
PowerShell Operational logging, when script block logging is enabled, captures the full content of scripts and commands executed, including those run by attackers. This makes it the most reliable artifact for reconstructing the exact PowerShell activity. Other artifacts like Prefetch or Security logs may show that PowerShell ran but not what it executed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Security Event Log
Why it's wrong here
The Security log records events such as logon/logoff, privilege use, and object access, but it does not capture PowerShell command details. While it may show process creation if audit policies are configured, it lacks the granular command-line data provided by PowerShell logging. Therefore, it is not the best source for the exact commands executed.
- ✗
ConsoleHost_history.txt file
Why it's wrong here
The ConsoleHost_history.txt file stores commands typed interactively into the PowerShell console by a user. However, it does not capture commands executed by scripts or remote sessions, and it can be easily deleted by an attacker. In this scenario, where a script was likely used, this file may not contain the relevant commands.
- ✗
Prefetch files for PowerShell.exe
Why it's wrong here
Prefetch files indicate that PowerShell.exe was executed, including the number of times and last run time, but they do not record the specific commands or scripts that were run. They provide evidence of execution but not the content of the commands, so they cannot reveal the exact PowerShell commands used in this attack.
- ✓
PowerShell Operational Event Log
Why this is correct
The PowerShell Operational log (Microsoft-Windows-PowerShell/Operational) records detailed information about PowerShell execution, including script block logging (Event ID 4104) and engine state changes. If script block logging is enabled, the actual commands executed are captured, making this the correct artifact for determining the exact PowerShell commands used.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.