Sample questions
GIAC Certified Forensic Analyst practice questions
An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to…
Enterprise Environment Incident ResponsemediumSee the answer and why each option is right or wrong →An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?
An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs.…
Identification of Malicious and Normal ActivityhardSee the answer and why each option is right or wrong →When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?
Introduction to File System Timeline ForensicsmediumSee the answer and why each option is right or wrong →An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source…
Identification of Malicious and Normal ActivitymediumSee the answer and why each option is right or wrong →An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unch…
Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?
Analyzing Volatile and Windows Event ArtifactsmediumSee the answer and why each option is right or wrong →An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting t…
Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?
Analyzing Volatile and Windows Event ArtifactshardSee the answer and why each option is right or wrong →When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific proc…
Analyzing Volatile and Windows Event ArtifactsmediumSee the answer and why each option is right or wrong →An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that th…
Introduction to File System Timeline ForensicseasySee the answer and why each option is right or wrong →An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Whic…
Analyzing Volatile and Windows Event ArtifactsmediumSee the answer and why each option is right or wrong →A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examini…
Analyzing Volatile and Windows Event ArtifactshardSee the answer and why each option is right or wrong →An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modificatio…
An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot…
Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?
An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.…
An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the e…
A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the…
An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processe…
Analyzing Volatile and Windows Event ArtifactshardSee the answer and why each option is right or wrong →During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the…
When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?
An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread b…
Analyzing Volatile and Windows Event ArtifactsmediumSee the answer and why each option is right or wrong →During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to dete…