GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
Exhibit
Refer to the exhibit: { 'Process': 'svchost.exe', 'PID': 1234, 'ParentPID': 567, 'Path': 'C:\\Windows\\System32\\', 'StartTime': '2023-10-01T10:00:00Z', 'CommandLine': 'C:\\Windows\\System32\\svchost.exe -k netsvcs' }Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?
⚠ Common exam trap
Candidates often assume that a process named 'svchost.exe' is legitimate if the file path is correct, failing to verify the parent process that spawned it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ParentPID value
The process name 'svchost.exe' is a common target for masquerading. While the path seems correct, the Parent Process ID (PPID) is the critical indicator. A legitimate svchost.exe should always be spawned by 'services.exe'. If the PPID 567 points to an unexpected process, such as an explorer.exe or a temporary file, it indicates a potential process masquerading or injection attempt, warranting immediate deep-dive analysis of that parent process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The command line contains -k netsvcs
Why it's wrong here
The -k netsvcs flag is a perfectly standard and legitimate command-line argument for the Windows service host process. It indicates that the process is correctly hosting a group of services, which is expected behavior for a system-critical process like svchost.exe on a standard Windows installation.
- ✗
The process path is C:\Windows\System32\
Why it's wrong here
This is the standard, expected location for the svchost.exe binary on a Windows operating system. Seeing the process running from the correct System32 directory is typically a sign of normal activity, not a reason for suspicion, unless other indicators of compromise are present in the environment.
- ✓
The ParentPID value
Why this is correct
Svchost.exe is a critical system process that should always be spawned by services.exe. If the PPID does not match the process ID of services.exe, it strongly suggests that the process is a masquerading binary or has been launched by an unauthorized actor, even if the path appears correct.
- ✗
The process name is svchost.exe
Why it's wrong here
Svchost.exe is a standard Windows service host process. The mere presence of this process name is not an indicator of compromise; rather, one must look at the path, the parent process, and the services it is hosting to determine if the instance is legitimate or malicious.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.