Courseiva

CCNA Analyzing Volatile and Windows Event Artifacts Questions

36 questions · Analyzing Volatile and Windows Event Artifacts · All types, answers revealed

1
MCQmedium

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

A.The user performed an interactive console logon
B.The authentication utilized NTLMv1 or failed to negotiate encryption
C.The event represents a Kerberos ticket granting service request
D.The account was locked out due to excessive attempts
AnswerB

A key length of 0 in an NTLM authentication event is a strong indicator of NTLMv1 usage or a failure to negotiate session security. This is critical for forensic analysts because NTLMv1 is cryptographically weak, and its presence often signals that an attacker is attempting to downgrade the authentication protocol.

Why this answer

A Logon Type 3 indicates a network logon, typically associated with accessing a shared resource or remote service. The 'NtLmSsp' package signifies NTLM authentication, and the Key Length of 0 indicates that NTLMv1 is being used or encryption is absent. This suggests a legacy or potentially insecure authentication attempt, which is a common indicator of lateral movement using outdated protocols that are susceptible to relay attacks.

Exam trap

Candidates often mistake a Logon Type 3 for a simple interactive login or misinterpret the NTLM key length as a successful encryption attempt rather than a indicator of legacy/weak protocols.

2
MCQmedium

Which of the following best describes the function of the 'UserAssist' registry key in a Windows forensic investigation?

A.Tracks all system-wide driver installations and updates.
B.Records the last time a user logged onto the system.
C.Tracks the execution of GUI-based applications for each user.
D.Stores the history of web browsing sessions in Internet Explorer.
AnswerC

UserAssist stores a record of applications executed by a specific user through the Windows shell. It tracks the name, path, execution count, and the last time it was run. It is a highly reliable source for forensic analysts needing to prove that a user interacted with a specific piece of software.

Why this answer

UserAssist records information about GUI-based programs executed by a user, including the file path, execution count, and last execution time. It is stored in the user's NTUSER.DAT hive. This artifact is essential for determining user activity, establishing which applications were launched, and identifying the persistence of specific malicious binaries across sessions.

It helps investigators prove that a specific user was responsible for launching an application, which is crucial for attribution.

Exam trap

Test-takers often confuse UserAssist with command-line history or background service execution, missing the specific focus of UserAssist on GUI-based user applications.

3
MCQmedium

Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?

A.Search for the process name in the Shimcache
B.Decode the base64 string and perform script analysis
C.Check the MFT for the parent process file
D.Run a system file integrity check
AnswerB

Decoding the base64 string is the only way to reveal the underlying PowerShell script executed by the attacker. This allows the analyst to see the actual commands, identify the targeted actions, and determine the scope of the incident, which is essential for creating an effective remediation plan for the compromised host.

Why this answer

The command line uses the '-enc' parameter, indicating a base64-encoded PowerShell script. Forensic analysts must decode this string to understand the attacker's intent. Once decoded, the analyst can identify the actual commands being run—such as downloading additional payloads or communicating with C2 servers.

This is critical in modern incident response because obfuscation is a routine tactic to evade basic keyword-based monitoring and initial detection by security analysts.

Exam trap

Candidates often assume running a static file analysis or searching for malicious domain names directly on the exhibit is sufficient, forgetting that '-enc' demands immediate decoding of the obfuscated PowerShell script before any other progress.

4
MCQmedium

During a live response on a Windows 10 workstation suspected of lateral movement, you capture volatile memory and also export the Windows Event Logs. You need to correlate a process that was running at the time of capture with its parent process and the user account that launched it, using only the memory image. Which Volatility 3 plugin should you run to produce a parent-child process tree with PID/PPID, image name, and offset columns?

A.windows.getsids
B.windows.pstree
C.windows.pslist
D.windows.psscan
AnswerB

windows.pstree walks the ActiveProcessLinks list and prints each process with its PID, PPID, image name, and offset, rendering an indented tree. This directly exposes parent-child relationships at capture time, letting you tie a suspicious child to the process that spawned it and, by cross-referencing windows.getsids or windows.cmdline, to the launching user context.

Why this answer

The goal is a parent-child process tree with PID, PPID, and image name from a memory image. The pstree plugin is purpose-built for that: it traverses the active process list and renders indentation that shows lineage. Other plugins either list processes flatly, hunt for hidden or terminated objects, or resolve SIDs, none of which produce the tree structure required here.

Exam trap

The trap here is assuming any process-listing plugin shows lineage; pslist shows PPID as a column but does not construct the parent-child tree that pstree does.

5
MCQeasy

A Windows 10 endpoint was compromised, and the attacker cleared the Security event log after establishing persistence. You have a memory image captured after the clearing. Which Windows Event Log artifact can still provide evidence of the log-clearing action, even if the Security log entries were wiped?

A.Security log Event ID 1102
B.Application log Event ID 1000
C.System log Event ID 6005
D.System log Event ID 104
AnswerD

When the Windows Event Log service clears a log, it writes Event ID 104 to the System log, recording which log was cleared and by which user. Even if the Security log itself is emptied, this System log entry persists unless the System log is also cleared, making it a reliable indicator of log tampering.

Why this answer

Clearing a log generates Event ID 1102 in the Security log and Event ID 104 in the System log. Because the Security log was erased, the 1102 entry is gone, but the System log's 104 entry usually remains and records the log name and the user who performed the clear. That surviving record is the key artifact for proving anti-forensic activity.

Exam trap

The trap here is reaching for the well-known Security 1102 event; it is written into the log being cleared, so it is destroyed along with it, while the System 104 entry persists.

6
MCQmedium

An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?

A.windows.pslist
B.windows.cmdline
C.windows.netscan
D.windows.malfind
AnswerD

The malfind plugin scans process memory for regions that are both executable and writable, and that do not map to a file on disk. It then displays the start address of threads within those regions, which is a strong indicator of injected code. This directly addresses the requirement to find threads starting outside legitimate modules.

Why this answer

The malfind plugin is designed to detect hidden or injected code in memory by identifying memory regions that are both writable and executable and that lack a corresponding file on disk. It also reports the start address of threads within those regions. This makes it the correct choice for finding threads that start outside of legitimate modules, which is a common indicator of process injection or fileless malware.

Exam trap

The trap here is assuming that a process listing plugin like pslist will reveal injected code, when in fact malfind is needed to inspect memory protections and thread start addresses.

7
MCQeasy

An analyst is examining a Windows system and needs to determine when a USB mass storage device was last connected. Which registry artifact should be examined to find the device's first and last connection times?

A.The NTUSER.DAT hive under Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
B.The SECURITY hive under Policy\Secrets
C.The SOFTWARE hive under Microsoft\Windows\CurrentVersion\Uninstall
D.The SYSTEM hive under CurrentControlSet\Enum\USBSTOR
AnswerD

The USBSTOR key in the SYSTEM hive records USB mass storage devices and, within each device instance, the Properties subkey holds timestamps such as the first and last connection times. This makes it the correct artifact for determining when a USB device was last connected to the system.

Why this answer

USB mass storage devices are enumerated under CurrentControlSet\Enum\USBSTOR in the SYSTEM hive, and each device instance includes a Properties subkey with timestamps for first and last connection. Examining that key therefore provides the device identity and the connection timing needed to establish when the device was last attached to the system.

Exam trap

The trap here is choosing MountPoints2 for USB timing, when that key reflects per-user mount history rather than the device's first and last connection timestamps.

8
MCQhard

During an investigation of a compromised Windows Server 2019, an analyst extracts the ShimCache (AppCompatCache) from the SYSTEM registry hive. The analyst needs to determine which executable was present on the system but may have been deleted. Which artifact within the ShimCache entry provides the best indication of file existence and last modification time?

A.The SHA256 hash of the executable
B.The execution flag and run count
C.The process ID and parent process ID
D.The file path and last modified timestamp
AnswerD

The ShimCache entry contains the full file path and, on Windows 8 and later, a last modified timestamp from the file's $STANDARD_INFORMATION attribute. This timestamp indicates when the file was last modified, not when it was executed. However, the presence of a path in ShimCache confirms the file existed on the system at some point, which is valuable for identifying deleted executables. This makes it the correct choice for determining file existence and last modification time.

Why this answer

ShimCache entries include the file path and, on Windows 8+, a last modified timestamp from the file's $STANDARD_INFORMATION attribute. This timestamp helps determine when the file was last modified, and the presence of the path confirms the file existed. Execution flags and run counts are not part of ShimCache; those are in UserAssist or Prefetch.

Process IDs and hashes are also not stored in ShimCache.

Exam trap

The trap here is confusing ShimCache with artifacts like UserAssist or AmCache that track execution or hashes; ShimCache only records file paths and last modified times.

9
MCQeasy

Which artifact is the primary location for finding 'Shellbag' data, which tracks user folder access history?

A.SYSTEM hive
B.NTUSER.DAT hive
C.SOFTWARE hive
D.SAM hive
AnswerB

Shellbags are stored in the user-specific NTUSER.DAT registry hive. They track folder access, directory view settings, and navigation history. This registry key is the authoritative source for reconstructing a user's interaction with the file system, providing key evidence of which folders were browsed during the period of interest.

Why this answer

Shellbags are stored in the NTUSER.DAT registry hive. They provide an invaluable record of which folders a user has opened and the specific view settings applied to those folders. This artifact is critical for forensic investigations because it proves user presence in specific directories, which can be used to link a user account to the staging of malicious files or the browsing of sensitive data during an incident.

Exam trap

Candidates often incorrectly guess the SYSTEM hive or SOFTWARE hive, forgetting that Shellbags are user-specific artifacts stored within the individual user's NTUSER.DAT registry file.

10
MCQmedium

A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?

A.The file C:\Windows\System32\Tasks\<TaskName> in the Task Scheduler store
B.The Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders key in the SOFTWARE hive
C.The Microsoft\Windows NT\CurrentVersion\Winlogon key's Shell value in the SOFTWARE hive
D.The Software\Microsoft\Windows\CurrentVersion\Run key in the NTUSER.DAT hive
AnswerA

The Task Scheduler stores each task as an XML file under C:\Windows\System32\Tasks, named after the task path. That XML contains the Actions (the executable and arguments) and Triggers, including logon triggers, so examining it directly reveals the suspicious binary and the logon trigger configured for persistence.

Why this answer

Scheduled tasks are defined as XML files in the Task Scheduler store under C:\Windows\System32\Tasks, and each file includes the task's Triggers and Actions. A logon trigger with an action launching a suspicious binary is exactly the persistence configuration described, so inspecting that XML file directly reveals both the executable and the trigger that causes it to run at logon.

Exam trap

The trap here is confusing registry autostart locations such as Run or Winlogon Shell with scheduled tasks, when only the Task Scheduler store holds task actions and triggers.

11
MCQhard

You are reviewing a Windows 10 host for evidence of process execution. A suspect binary was deleted from disk, but you need to prove it actually ran. Which artifact provides the strongest evidence that the specific executable was launched, independent of any prefetch or shimcache entries?

A.A Prefetch file (.pf) containing the binary's name and run count in C:\Windows\Prefetch
B.The Amcache.hve entry containing the binary's SHA-1 hash and path
C.Security event 4688 with the New Process Name field populated for the binary
D.The AppCompatCache (ShimCache) entry for the binary in the SYSTEM hive
AnswerC

Event ID 4688 is written to the Security log when a new process is created, and with process creation auditing enabled it records the New Process Name and often the command line. It is generated at the moment of execution and does not depend on Prefetch or ShimCache, making it the strongest independent proof that the specific executable ran.

Why this answer

Event ID 4688 is generated by the Windows auditing subsystem at the instant a process is created, capturing the new process image path and, when command-line auditing is enabled, the full command line. Unlike ShimCache or Amcache, which can be populated by file presence or scanning, 4688 only appears when execution occurs, so it independently proves the suspect binary was launched.

Exam trap

The trap here is treating file-observation artifacts such as ShimCache or Amcache as proof of execution, when they can record files that were merely present or scanned.

12
Multi-Selectmedium

A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)

Select 2 answers
A.windows.pslist
B.windows.handles
C.windows.psscan
D.windows.cmdline
E.windows.pstree
AnswersA, C

windows.pslist walks the active process list (PsActiveProcessHead) to enumerate processes that were active at the time of capture. It provides a list of processes with their PIDs, PPIDs, and other details, but it may miss processes that have terminated or are hidden.

Why this answer

windows.pslist enumerates processes from the active process list, while windows.psscan scans memory for process structures, which can uncover terminated or hidden processes. Using both provides a more comprehensive view of processes that were running or had recently terminated. The other plugins either rely on the same active list or serve different purposes.

Exam trap

The trap here is assuming that pstree provides an independent process enumeration method; it actually uses the same active process list as pslist and does not scan for hidden processes.

13
MCQmedium

An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?

A.pslist
B.handles
C.malfind
D.pstree
AnswerC

Malfind specifically scans for VAD nodes marked as PAGE_EXECUTE_READWRITE that lack an associated mapped file. This is the primary signature of injected code or hollowed processes where attackers have manually allocated memory to house malicious payloads. It provides the necessary visibility into anomalous memory protections within target processes.

Why this answer

The malfind plugin is the standard tool for identifying injected code by scanning for memory segments with Execute/Read/Write permissions that are not backed by a file on disk. This is a critical step in volatile memory analysis because malware often uses process hollowing to hide its execution flow within legitimate system processes. Comparing VAD protections helps confirm the anomaly, which is a hallmark of sophisticated persistent threats evading standard file-based detection.

Exam trap

Examinees often confuse basic process enumeration plugins with memory injection detectors, failing to utilize specialized tools that evaluate VAD permissions and unbacked memory regions.

14
MCQeasy

An analyst is examining a Windows 10 system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log should be examined to find the most recent interactive logon event?

A.Application Event Log, Event ID 1000
B.Security Event Log, Event ID 4624 with Logon Type 2
C.Security Event Log, Event ID 4634
D.System Event Log, Event ID 6005
AnswerB

Event ID 4624 in the Security log records successful logon attempts. Logon Type 2 indicates an interactive logon at the console. By filtering for Event ID 4624 and Logon Type 2, an analyst can identify the most recent interactive logon. This is the correct source for determining when a user last logged on interactively.

Why this answer

Security Event ID 4624 with Logon Type 2 records interactive logons at the console. By examining the most recent such event, an analyst can determine when a user last logged on interactively. System Event ID 6005 relates to service startup, Application Event ID 1000 to application crashes, and Security Event ID 4634 to logoffs, none of which answer the question.

Exam trap

The trap here is confusing logon and logoff events or looking in the wrong log; interactive logons are recorded as Event ID 4624 with Logon Type 2 in the Security log.

15
MCQmedium

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

A.The command line contains -k netsvcs
B.The process path is C:\Windows\System32\
C.The ParentPID value
D.The process name is svchost.exe
AnswerC

Svchost.exe is a critical system process that should always be spawned by services.exe. If the PPID does not match the process ID of services.exe, it strongly suggests that the process is a masquerading binary or has been launched by an unauthorized actor, even if the path appears correct.

Why this answer

The process name 'svchost.exe' is a common target for masquerading. While the path seems correct, the Parent Process ID (PPID) is the critical indicator. A legitimate svchost.exe should always be spawned by 'services.exe'.

If the PPID 567 points to an unexpected process, such as an explorer.exe or a temporary file, it indicates a potential process masquerading or injection attempt, warranting immediate deep-dive analysis of that parent process.

Exam trap

Candidates often assume that a process named 'svchost.exe' is legitimate if the file path is correct, failing to verify the parent process that spawned it.

16
MCQmedium

An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?

A.Security.evtx
B.System.evtx
C.WMI-Activity/Operational.evtx
D.Application.evtx
AnswerC

This log file specifically captures WMI events, including requests, queries, and process creation triggered by the WMI service. It is the most direct artifact for identifying malicious WMI activity, providing the necessary evidence to confirm that an attacker utilized this specific management interface for remote code execution.

Why this answer

The 'Microsoft-Windows-WMI-Activity/Operational' log is the primary source for tracking WMI interactions. WMI is frequently abused for lateral movement because it allows for stealthy, authenticated command execution. By reviewing these specific operational logs, analysts can correlate WMI provider activity with process creation events, confirming whether a remote actor utilized WMI to launch malicious processes on the target system without needing an interactive shell session.

Exam trap

Candidates often check general security logs (4688) which show the process but lack the context of the remote WMI invocation that triggered the execution.

17
MCQmedium

An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?

A.The SRUM database entry for svchost.exe
B.The $MFT record for the svchost.exe file
C.The digital signature of the svchost.exe file
D.The Prefetch file for svchost.exe
AnswerC

Checking the digital signature verifies whether the executable is signed by Microsoft and has not been tampered with. A legitimate svchost.exe should be signed by Microsoft and reside in System32. If the signature is invalid or missing, it indicates a masquerading attempt, directly addressing the analyst's need to verify integrity and origin.

Why this answer

Verifying the digital signature of the executable is the most direct way to confirm whether svchost.exe is the legitimate Microsoft binary. A valid signature from Microsoft indicates the file is authentic and unmodified, while an invalid or missing signature suggests masquerading. Other artifacts like Prefetch, $MFT, and SRUM provide contextual information but do not verify integrity and origin.

Exam trap

The trap here is relying on execution artifacts like Prefetch or SRUM to prove legitimacy, when only signature verification can confirm the binary's authenticity.

18
MCQmedium

Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?

A.pstree
B.cmdline
C.netscan
D.dlllist
AnswerB

The cmdline plugin specifically retrieves the command-line arguments from the process's PEB (Process Environment Block). This provides the full string used to start the process, which often includes malicious paths, obfuscated arguments, or external command-and-control parameters that are vital for forensic analysis of the execution.

Why this answer

The 'cmdline' plugin in Volatility 2 or the equivalent 'windows.cmdline' in Volatility 3 is essential for surfacing the exact arguments used to launch a process. Attackers frequently use command-line arguments to pass encoded payloads, configure malicious scripts, or perform lateral movement tasks. Identifying these arguments provides the context necessary to understand the intent of the process, which is often hidden when looking only at the process name or binary path.

Exam trap

Candidates often select generic process listing plugins like 'pslist' which only show process names, forgetting that specific argument flags require dedicated command-line extraction plugins.

19
Multi-Selecthard

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Select 3 answers
A.Memory Page Permissions (RWX)
B.The system's Event Log files
C.Unbacked executable memory
D.The MFT file records
E.Discrepancies in the Process VAD tree
AnswersA, C, E

Executable memory regions that are marked as Read-Write-Execute (RWX) are highly suspicious. Legitimate processes rarely require memory to be writable and executable simultaneously. Attackers often use these permissions to write shellcode to a buffer and then execute it, making this a primary indicator of process injection.

Why this answer

Process injection techniques often modify memory protections or inject code into existing legitimate processes. By comparing the disk-based image of a process with its memory-based representation, analysts can identify discrepancies in executable sections. Checking memory protections (e.g., RWX permissions) and identifying unbacked executable code in private memory regions are the primary methods for uncovering sophisticated persistent threats that operate entirely within the volatile memory space.

Exam trap

Candidates often focus on file hashes or process names, which are easily spoofed, rather than inspecting memory-specific indicators like VAD tree anomalies or RWX memory regions.

20
MCQhard

You are examining a Windows Server 2019 memory image after a suspected credential-theft incident. You need to identify which process was used to access the LSASS process memory at the time of capture. Which Volatility 3 plugin and artifact combination most directly reveals handles opened to the LSASS process by other processes?

A.windows.netscan, filtering for connections owned by lsass.exe
B.windows.dlllist, focusing on unsigned DLLs loaded into lsass.exe
C.windows.malfind, looking for PAGE_EXECUTE_READWRITE regions in lsass.exe
D.windows.handles, filtering for handles to the lsass.exe process object
AnswerD

windows.handles enumerates the handle table of each process and shows the object type and object name. Filtering for lsass.exe reveals which processes held handles to the LSASS process object, providing direct evidence of access at capture time. This is the most targeted way to identify a process that opened LSASS for memory access.

Why this answer

Handle tables record which process opened an object and what type it is. Filtering the handle output for the lsass.exe process object pinpoints processes that held a handle to LSASS at capture time, which is strong evidence of memory access. Injected-memory, network, and loaded-module plugins examine other artifacts and do not answer who opened the handle.

Exam trap

The trap here is conflating injected memory inside LSASS with a handle opened to LSASS; malfind finds the former, while the handle table shows the latter.

21
MCQmedium

When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?

A.DNS cache
B.TCP Endpoint structures
C.Shimcache
D.Amcache.hve
AnswerB

TCP Endpoint structures in memory store the state of all active and listening network connections, including the associated process ID. By parsing these structures from a memory dump, an analyst can definitively link network traffic to a specific, potentially malicious process, regardless of whether the connection is hidden from standard OS tools.

Why this answer

The TCP Endpoint structures in kernel memory are essential for mapping network activity to process ownership. Attackers often attempt to hide connections using rootkit techniques, but these structures in memory usually remain accurate. Linking a specific PID to a remote IP address allows the analyst to identify Command and Control (C2) communication, which is the most reliable way to identify an active, compromised host during a live incident response.

Exam trap

Candidates often suggest checking netstat output or active connection logs, which can be hooked or hidden by rootkits, rather than inspecting the kernel-level TCP structures.

22
MCQeasy

An analyst is reviewing a Windows 10 system and wants to determine the last time the system was shut down. Which Windows event log and event ID should the analyst examine?

A.System log, event ID 6006
B.Security log, event ID 4647
C.Application log, event ID 1001
D.System log, event ID 6013
AnswerA

Event ID 6006 in the System log indicates that the event log service was stopped, which occurs during a clean shutdown. It is a reliable indicator of a graceful system shutdown. The timestamp of this event provides the time the shutdown process completed. This is the standard event used to determine shutdown time.

Why this answer

The System event log records event ID 6006 when the event log service is stopped during a clean shutdown. This event is a definitive indicator that the system was shut down gracefully. By examining the timestamp of event 6006, the analyst can determine the last shutdown time.

Other events like 6013 provide uptime but not shutdown time.

Exam trap

The trap here is confusing user logoff events or periodic uptime events with the actual system shutdown event, which is specifically recorded as event ID 6006 in the System log.

23
MCQhard

During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?

A.The Security ID (SID) of the account in the 4624 event
B.The Logon Process and Authentication Package fields in the 4624 event
C.The Logon GUID field in the 4624 event
D.The Process ID and Process Name fields in the 4624 event
AnswerB

The Logon Process and Authentication Package fields distinguish a network logon initiated by a service (for example, NTLM or Kerberos via a service host) from an interactive or explicit credential use. A mismatch, such as an unexpected authentication package or logon process for that account, is a strong indicator of credential misuse for lateral movement rather than normal service behavior.

Why this answer

For a Logon Type 3 event, the Logon Process and Authentication Package fields reveal the mechanism used. A service account authenticating via its normal service process and package looks routine; the same account authenticating with an unexpected package or from an unusual logon process suggests credential theft and lateral movement. The other fields support correlation but do not distinguish method as directly.

Exam trap

The trap here is focusing on the account name or SID to judge legitimacy; the same account can be used legitimately or maliciously, so the authentication method fields are what differentiate the two.

24
MCQhard

A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?

A.Enable the 'Turn on PowerShell Script Block Logging' policy under Administrative Templates > Windows Components > Windows PowerShell.
B.Enable the 'Process Creation' audit policy under Local Policies > Audit Policy.
C.Enable the 'Include command line in process creation events' policy under Administrative Templates > System > Audit Process Creation.
D.Enable the 'Audit Process Creation' policy under Advanced Audit Policy Configuration > Detailed Tracking.
AnswerC

This policy, when enabled, configures Windows to include the full command line in Event ID 4688 process creation events. Without it, the command line field is blank. Enabling it ensures future events capture this critical detail for forensic analysis.

Why this answer

The 'Include command line in process creation events' policy is the specific setting that controls whether the command line is recorded in Event ID 4688. Enabling it ensures that future process creation events contain the full command line, which is essential for identifying malicious commands. Other audit policies enable the event but do not add command line data.

Exam trap

The trap here is assuming that enabling process creation auditing automatically includes command line data; in reality, a separate policy must be enabled to capture that detail.

25
MCQmedium

An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?

A.A process named cmd.exe spawned a PowerShell process, which could indicate scripted or malicious activity.
B.The system automatically started a PowerShell process as part of a scheduled task.
C.PowerShell was used to execute a command that created cmd.exe.
D.A user manually opened a command prompt and then launched PowerShell.
AnswerA

Event ID 4688 records the creation of a new process and includes the creator process name. Here, cmd.exe is the creator of powershell.exe. This parent-child relationship is a common technique in malicious scripts, such as those used in fileless attacks or lateral movement. It does not prove maliciousness but is a suspicious pattern that warrants further investigation. This option accurately describes the event.

Why this answer

Event ID 4688 includes the creator process name and new process name. In this case, cmd.exe created powershell.exe, indicating a parent-child relationship that is often seen in malicious scripts, such as those that use PowerShell for download or execution. While it could be benign, it is a suspicious pattern that should be investigated further.

The other options either assume benign user action, introduce unsupported context, or reverse the relationship.

Exam trap

The trap here is assuming that any cmd.exe to powershell.exe chain is malicious, but it can be benign; however, the event itself only describes the relationship, not intent.

26
MCQmedium

An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Which event ID should the analyst examine to find this information?

A.4625
B.4647
C.4624
D.4634
AnswerC

Event ID 4624 is logged when a logon attempt succeeds. It includes the logon type, which indicates the type of logon (e.g., interactive, network, batch). For interactive logons, the logon type is 2 (Interactive) or 10 (RemoteInteractive). By filtering for these logon types and the specific user, the analyst can determine the last interactive logon time.

Why this answer

Event ID 4624 is the primary event for successful logons. It contains detailed information including the logon type, which distinguishes interactive (type 2 or 10) from network (type 3) or other logons. By filtering for the specific user account and logon types 2 and 10, the analyst can identify the most recent interactive logon.

This is a standard technique in Windows forensic analysis.

Exam trap

The trap here is confusing logon events with logoff events or failed logon events; only 4624 records successful logons, and the logon type must be considered to isolate interactive sessions.

27
MCQhard

During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?

A.The parent process has terminated, and the PPID is now stale.
B.The memory dump is corrupted and the process list is incomplete.
C.The process 'svchost.exe' is a known Windows service and its parent should always be 'services.exe'.
D.The PPID indicates that the parent process is hidden by a rootkit and should be recovered using psscan.
AnswerA

In Windows, when a parent process terminates, its child processes are not terminated. The PPID of a child remains pointing to the now-defunct parent PID. Since PID 1234 is not in the active process list, it likely terminated, leaving a stale PPID. This is a common forensic artifact and does not necessarily indicate malicious activity.

Why this answer

When a parent process terminates, its child processes continue to run, and the child's PPID remains set to the now-invalid parent PID. This results in a stale PPID. The absence of PID 1234 in the active process list indicates that the parent has likely terminated, which is a normal occurrence and not inherently malicious.

Exam trap

The trap here is assuming that a missing parent process automatically indicates a hidden process or rootkit, when it is often just a terminated parent.

28
Multi-Selecthard

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Select 2 answers
A.windows.dlllist
B.windows.ldrmodules
C.windows.vadinfo
D.windows.handles
E.windows.malfind
AnswersC, E

The windows.vadinfo plugin lists virtual address descriptors (VADs) for a process, showing memory regions and their protections. It helps identify unusual memory allocations, such as those with execute permissions that are not backed by a file, which are indicative of injected code. It complements malfind by providing detailed VAD information.

Why this answer

The windows.malfind and windows.vadinfo plugins are both designed to analyze process memory for suspicious regions. malfind identifies and dumps potentially injected code based on memory protection and file backing, while vadinfo provides a detailed view of all VADs, helping analysts spot anomalous memory allocations that may contain injected code.

Exam trap

The trap here is assuming that any plugin listing DLLs or handles will detect code injection, when injection often involves non-DLL memory regions.

29
Multi-Selecthard

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Select 2 answers
A.The process's token indicates it is running with elevated privileges.
B.The process's image path in memory does not match the file path on disk.
C.The process's parent process ID (PPID) is a non-existent process.
D.The process has a thread start address that points to a memory region not backed by a file on disk.
E.The process has a large number of open handles to remote named pipes.
AnswersB, D

In process hollowing, the original executable is created in a suspended state, its memory is unmapped, and malicious code is injected. The in-memory image path (from the PEB) may still point to the original file, but the actual code in memory is different. A mismatch between the in-memory image path and the on-disk file path, or a discrepancy in the code, is a strong indicator. This is often detected by comparing the in-memory module with the disk file.

Why this answer

Process hollowing involves creating a legitimate process in a suspended state, unmapping its memory, and injecting malicious code. This results in two key indicators: the in-memory image path may not match the disk file (or the memory content differs from disk), and threads execute from memory regions not backed by a file. These artifacts are directly tied to the hollowing technique and are detectable through memory analysis.

Exam trap

The trap here is focusing on generic indicators like elevated privileges or missing parent processes, which are not specific to process hollowing, rather than the memory-centric artifacts that directly reveal the technique.

30
MCQmedium

An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?

A.windows.dlllist
B.windows.handles
C.windows.threads
D.windows.malfind
AnswerC

windows.threads lists all threads for a given process, including thread IDs, start addresses, and stack information. This allows an analyst to identify threads whose start addresses fall outside the normal module range, which is a strong indicator of code injection. It directly addresses the requirement to examine threads and their start addresses in volatile memory, making it the correct choice.

Why this answer

The windows.threads plugin enumerates threads within a process, showing start addresses that can be compared against known module ranges. Injected threads often have start addresses in unbacked memory, making this plugin ideal for detecting code injection. The other plugins focus on memory regions, handles, or loaded modules, none of which provide thread-level detail needed to identify an injected thread.

Exam trap

The trap here is assuming that windows.malfind is always the best plugin for detecting code injection, but it only scans memory regions and does not enumerate threads or their start addresses.

31
MCQmedium

A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?

A.The windows.cmdline plugin output from the memory image showing the PowerShell process command line.
B.Windows Security event log, event ID 4688 (Process Creation) with command-line auditing enabled.
C.The windows.pslist plugin output showing the PowerShell process and its parent process.
D.Windows PowerShell event log, event ID 4104 (Script Block Logging).
AnswerD

Event ID 4104 in the Windows PowerShell operational log records the actual script block text when Script Block Logging is enabled. This directly captures the PowerShell code that was executed, including obfuscated or dynamically generated content, making it the most direct source for reconstructing the malicious script block. It is not enabled by default, so its presence indicates prior configuration.

Why this answer

Script Block Logging (event ID 4104) captures the actual PowerShell code that runs, including obfuscated or dynamically constructed script blocks, and writes it to the Windows PowerShell operational log. This is the most direct artifact for determining what a malicious PowerShell script did. Command-line auditing and memory plugins can show how PowerShell was launched but not the full script content.

Therefore, the PowerShell event log with 4104 is the best source.

Exam trap

The trap here is assuming that command-line auditing or memory command-line plugins capture the full PowerShell script, when they only show how the process was started and not the script blocks executed at runtime.

32
MCQmedium

During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?

A.The Security event log entry 4624 with Logon Type 2 recorded at the time of the incident
B.The NTUSER.DAT registry hive loaded in the user's profile folder
C.The Security event log entry 4634 recording a logoff event
D.The Security event log entry 4647 recording a user-initiated logoff
AnswerA

Event ID 4624 with Logon Type 2 indicates an interactive logon at the console, recorded in the Security log at the moment the session was established. In this scenario it directly ties a specific account to a physical or console session, making it the most reliable artifact for confirming who was actively logged in at the time of the incident.

Why this answer

An interactive logon is recorded as Security event 4624 with Logon Type 2, which is generated when a user authenticates at the console. Because the question asks who was actively logged on at the moment of the incident, that specific logon type is the most direct and reliable evidence, whereas logoff entries and profile hives persist or indicate termination rather than active presence.

Exam trap

The trap here is assuming that the presence of a user profile hive such as NTUSER.DAT proves an active interactive session, when it only proves the profile was loaded at some point.

33
MCQmedium

When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?

A.Event ID 4100
B.Event ID 4103
C.Event ID 4104
D.Event ID 400
AnswerC

Event ID 4104 logs the script block content executed by the PowerShell engine. This is the primary event for forensic analysis of PowerShell activity, as it captures the full script, including base64-encoded commands, allowing analysts to decode and analyze the malicious logic used in fileless attacks.

Why this answer

Event ID 4104 records the execution of a script block. Attackers frequently use PowerShell's -EncodedCommand parameter to bypass simple string-based signature detection. By analyzing the content of these logs, specifically looking for long, base64-encoded strings, analysts can decode the hidden payloads and reconstruct the attacker's actions, which is vital for understanding the full scope of a fileless attack that avoids traditional disk-based indicators.

Exam trap

Candidates frequently confuse Event ID 4104 (Script Block Logging) with Event ID 4103 (Module Logging) or process creation events like 4688 when looking for PowerShell execution patterns.

34
MCQeasy

A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?

A.The windows.cmdline plugin output showing the command line of cmd.exe.
B.The Windows Event Log 'Microsoft-Windows-CommandPrompt/Operational' with command history events.
C.The console history buffer in the conhost.exe process memory.
D.The PowerShell console history file at %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt.
AnswerC

The Windows Console Host (conhost.exe) maintains a history buffer of commands entered in a command prompt window. This buffer resides in the memory of the conhost.exe process associated with the console session. Extracting this buffer from a memory image can reveal recently typed commands that may not be recorded in any persistent log, making it a valuable volatile artifact for user activity.

Why this answer

The console history buffer in conhost.exe memory contains the commands typed in a command prompt window during the session. This volatile artifact is not written to disk by default, so it can only be recovered from a memory image. The PSReadLine history file is for PowerShell and is persistent, while event logs and cmdline plugins do not capture interactive command history.

Therefore, the conhost.exe buffer is the correct source.

Exam trap

The trap here is confusing PowerShell's persistent PSReadLine history file with cmd.exe console history, which is only held in conhost.exe memory and not saved to disk.

35
MCQmedium

An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?

A.Checking the file creation time in the MFT
B.Verifying the digital signature of the file
C.Searching for the process in the Shimcache
D.Viewing the process in Task Manager
AnswerB

A legitimate Windows system binary like svchost.exe will be signed by Microsoft. If the file in the AppData directory is unsigned, or if the signature is invalid, it is a definitive indicator that the file is not the genuine system binary, regardless of its filename or location.

Why this answer

Comparing the file's hash against known good values (e.g., from the National Software Reference Library) or checking digital signatures is standard forensic practice. Attackers often rename malicious binaries to match legitimate processes, but they cannot forge the cryptographic signature of a Microsoft-signed binary. If the file lacks a valid signature or has a mismatched hash, it confirms the binary is a malicious imposter intended to evade detection.

Exam trap

Analysts frequently rely only on file names, file sizes, or standard directory paths to validate system binaries, failing to notice that names like svchost.exe can be easily spoofed.

36
Multi-Selecthard

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Select 2 answers
A.windows.netscan
B.windows.vadinfo
C.windows.handles
D.windows.registry.hivelist
E.windows.malfind
AnswersB, E

windows.vadinfo dumps the virtual address descriptor tree for a process, showing each region's protection, commit type, and backing file. When combined with malfind, it lets you characterize the injected region by confirming whether it is private, executable, and fileless, which is essential for describing the injection in this scenario.

Why this answer

windows.malfind finds executable memory regions not backed by a file, which is the signature of injected code, while windows.vadinfo provides the virtual address descriptor details for those regions, including protection and commit type. Using them together lets the analyst detect the injection and then characterize it as private, executable, and fileless within the target process.

Exam trap

The trap here is selecting a network or handle plugin for injection analysis, when only memory-region plugins such as malfind and vadinfo reveal unbacked executable code.

Ready to test yourself?

Try a timed practice session using only Analyzing Volatile and Windows Event Artifacts questions.