Courseiva

GCFA Windows Artifact Analysis Practice Question

An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?

⚠ Common exam trap

The trap here is assuming prefetch files store command-line arguments or complete file access lists, when they only provide execution metadata.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It confirms that PowerShell was executed and provides the last execution time and number of times run.

The correct answer is that the prefetch file confirms execution and provides last execution time and run count. Prefetch files are created by the Windows Prefetcher to optimize application startup, and they include metadata such as the last run time and number of executions. This makes them a key artifact for determining if an executable like PowerShell was run, and when.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It contains the full command-line arguments used when PowerShell was launched.

    Why it's wrong here

    Prefetch files do not store command-line arguments. They record file and directory references used by the executable, but not the specific arguments passed. Command-line arguments are found in Event ID 4688 with command-line auditing, or in process memory, not in prefetch.

  • ✗

    It indicates that PowerShell was installed as a service on the system.

    Why it's wrong here

    Prefetch files are generated for executables that are run, not for services specifically. A service would still have an executable, but the prefetch file does not indicate service installation. Service installation is recorded in the System event log and registry, not in prefetch.

  • ✓

    It confirms that PowerShell was executed and provides the last execution time and number of times run.

    Why this is correct

    Prefetch files are created when an executable is run, and they record the last execution time and run count. The presence of a prefetch file for POWERSHELL.EXE indicates that PowerShell was executed on the system. The timestamp embedded in the .pf file can be parsed to determine the last execution time, which is valuable for timeline analysis.

  • ✗

    It provides a list of all files accessed by PowerShell during its execution.

    Why it's wrong here

    Prefetch files do not contain a complete list of files accessed. They store references to files and directories that the executable loaded or interacted with, but this is not an exhaustive list of all file accesses. The primary purpose is to speed up application launch, not to log file activity.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.