Courseiva

GCFA · domain

Analyzing Volatile and Windows Event Artifacts

This GCFA domain covers live-response and post-mortem analysis of memory and Windows event logs. Candidates must interpret process metadata, detect injection and hollowing, map network connections to PIDs, and read Security logon events. Questions use exhibits, multi-select, and scenario stems requiring tool-output interpretation rather than recall alone.

36 questions6 easy20 medium10 hard

Focused practice

Practice Analyzing Volatile and Windows Event Artifacts questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Analyzing Volatile and Windows Event Artifacts

Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.

Interpreting process metadata from memory tools like Volatility and Rekall for anomalies

Detecting process hollowing and code injection via memory artifacts and thread inspection

Correlating network connections to process IDs using netstat, Volatility netscan, and handles

Reading Windows Security event IDs for logon type, account, and interactive session timing

Watch out for

Common Analyzing Volatile and Windows Event Artifacts exam traps

  • ▸Confusing parent-child process relationships with injected code; a legitimate parent can spawn a hollowed child, so verify image path and memory mapping.
  • ▸Treating every hidden or unlinked connection as malicious; terminated processes and kernel structures can leave stale entries that require corroboration.
  • ▸Misreading logon event IDs: 4624 is a logon, 4625 failure, 4634 logoff, and logon type 2 versus 10 changes the interpretation entirely.

Question index

All Analyzing Volatile and Windows Event Artifacts questions (36)

Click any question to see the full explanation, or start a practice session above.

1

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

Medium
2

Which of the following best describes the function of the 'UserAssist' registry key in a Windows forensic investigation?

Medium
3

Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?

Medium
4

During a live response on a Windows 10 workstation suspected of lateral movement, you capture volatile memory and also export the Windows Event Logs. You need to correlate a process that was running at the time of capture with its parent process and the user account that launched it, using only the memory image. Which Volatility 3 plugin should you run to produce a parent-child process tree with PID/PPID, image name, and offset columns?

Medium
5

A Windows 10 endpoint was compromised, and the attacker cleared the Security event log after establishing persistence. You have a memory image captured after the clearing. Which Windows Event Log artifact can still provide evidence of the log-clearing action, even if the Security log entries were wiped?

Easy
6

An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?

Medium
7

An analyst is examining a Windows system and needs to determine when a USB mass storage device was last connected. Which registry artifact should be examined to find the device's first and last connection times?

Easy
8

During an investigation of a compromised Windows Server 2019, an analyst extracts the ShimCache (AppCompatCache) from the SYSTEM registry hive. The analyst needs to determine which executable was present on the system but may have been deleted. Which artifact within the ShimCache entry provides the best indication of file existence and last modification time?

Hard
9

Which artifact is the primary location for finding 'Shellbag' data, which tracks user folder access history?

Easy
10

A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?

Medium
11

You are reviewing a Windows 10 host for evidence of process execution. A suspect binary was deleted from disk, but you need to prove it actually ran. Which artifact provides the strongest evidence that the specific executable was launched, independent of any prefetch or shimcache entries?

Hard
12

A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)

Medium
13

An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?

Medium
14

An analyst is examining a Windows 10 system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log should be examined to find the most recent interactive logon event?

Easy
15

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

Medium
16

An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?

Medium
17

An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?

Medium
18

Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?

Medium
19

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Hard
20

You are examining a Windows Server 2019 memory image after a suspected credential-theft incident. You need to identify which process was used to access the LSASS process memory at the time of capture. Which Volatility 3 plugin and artifact combination most directly reveals handles opened to the LSASS process by other processes?

Hard
21

When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?

Medium
22

An analyst is reviewing a Windows 10 system and wants to determine the last time the system was shut down. Which Windows event log and event ID should the analyst examine?

Easy
23

During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?

Hard
24

A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?

Hard
25

An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?

Medium
26

An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Which event ID should the analyst examine to find this information?

Medium
27

During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?

Hard
28

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Hard
29

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Hard
30

An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?

Medium
31

A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?

Medium
32

During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?

Medium
33

When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?

Medium
34

A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?

Easy
35

An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?

Medium
36

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Hard

Frequently asked questions

What does the Analyzing Volatile and Windows Event Artifacts domain cover on the GCFA exam?
Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.
How many questions are in this domain?
This page lists all 36 Analyzing Volatile and Windows Event Artifacts questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Analyzing Volatile and Windows Event Artifacts questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcfa GIAC-GCFA analyzing volatile and windows event artifacts Practice Questions