Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

Exhibit

Refer to the exhibit: { 'Process': 'svchost.exe', 'PID': 1234, 'ParentPID': 567, 'Path': 'C:\\Windows\\System32\\', 'StartTime': '2023-10-01T10:00:00Z', 'CommandLine': 'C:\\Windows\\System32\\svchost.exe -k netsvcs' }

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

⚠ Common exam trap

Candidates often assume that a process named 'svchost.exe' is legitimate if the file path is correct, failing to verify the parent process that spawned it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ParentPID value

The process name 'svchost.exe' is a common target for masquerading. While the path seems correct, the Parent Process ID (PPID) is the critical indicator. A legitimate svchost.exe should always be spawned by 'services.exe'. If the PPID 567 points to an unexpected process, such as an explorer.exe or a temporary file, it indicates a potential process masquerading or injection attempt, warranting immediate deep-dive analysis of that parent process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The command line contains -k netsvcs

    Why it's wrong here

    The -k netsvcs flag is a perfectly standard and legitimate command-line argument for the Windows service host process. It indicates that the process is correctly hosting a group of services, which is expected behavior for a system-critical process like svchost.exe on a standard Windows installation.

  • ✗

    The process path is C:\Windows\System32\

    Why it's wrong here

    This is the standard, expected location for the svchost.exe binary on a Windows operating system. Seeing the process running from the correct System32 directory is typically a sign of normal activity, not a reason for suspicion, unless other indicators of compromise are present in the environment.

  • ✓

    The ParentPID value

    Why this is correct

    Svchost.exe is a critical system process that should always be spawned by services.exe. If the PPID does not match the process ID of services.exe, it strongly suggests that the process is a masquerading binary or has been launched by an unauthorized actor, even if the path appears correct.

  • ✗

    The process name is svchost.exe

    Why it's wrong here

    Svchost.exe is a standard Windows service host process. The mere presence of this process name is not an indicator of compromise; rather, one must look at the path, the parent process, and the services it is hosting to determine if the instance is legitimate or malicious.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.