Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

During a compromise assessment on a Windows 10 workstation, an analyst runs a volatile memory capture and inspects the process list in Volatility 3. The analyst observes a process named 'lsass.exe' with PID 872, whose parent process is 'winlogon.exe' with PID 640. The executable path recorded for lsass.exe is 'C:\Windows\System32\lsass.exe'. Which conclusion is BEST supported by these artifacts?

⚠ Common exam trap

The trap here is assuming that any lsass.exe parent other than services.exe indicates masquerading, when in fact winlogon.exe is the expected parent on a Windows workstation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The lsass.exe process appears consistent with a normal Windows host; the parent and image path match expected behavior.

Legitimate LSASS on Windows is launched by winlogon.exe from C:\Windows\System32\lsass.exe, and the captured parent-child relationship and image path both match that baseline. Because neither attribute deviates from expected behavior, the artifacts support a normal-host classification. Analysts should still corroborate with signature and handle inspection, but these particular memory artifacts do not indicate compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The lsass.exe process is a masquerading implant because its parent should always be services.exe.

    Why it's wrong here

    On Windows, the legitimate Local Security Authority Subsystem Service is spawned by winlogon.exe during interactive logon, not by services.exe. A parent of services.exe would itself be anomalous for lsass.exe. Therefore, the parent-child relationship shown here matches expected Windows behavior and does not by itself indicate masquerading, so this conclusion is unsupported by the artifacts.

  • ✗

    The lsass.exe process has been injected with a credential-dumping payload because its PID is not a multiple of four.

    Why it's wrong here

    Process IDs on Windows are allocated in multiples of four by the kernel object manager, and 872 is divisible by four, so the premise is factually incorrect. Even if the PID were unusual, PID arithmetic alone is never sufficient to conclude that LSASS memory has been injected. The artifacts shown do not demonstrate any credential-dumping behavior, making this conclusion unsupported.

  • ✗

    The lsass.exe process must have been relocated from its original directory because the System32 copy is reserved for svchost.exe.

    Why it's wrong here

    C:\Windows\System32 is the canonical location for lsass.exe, not svchost.exe, which also lives in System32 but is a separate service host process. There is no Windows behavior in which System32 is reserved for svchost.exe. The image path shown is exactly where the legitimate LSASS binary resides, so the assertion that it was relocated is incorrect.

  • ✓

    The lsass.exe process appears consistent with a normal Windows host; the parent and image path match expected behavior.

    Why this is correct

    Both the parent process (winlogon.exe) and the image path (C:\Windows\System32\lsass.exe) match the expected configuration for LSASS on a Windows 10 workstation. A masquerading lsass.exe would typically show a non-system path or an unexpected parent. These artifacts therefore support a benign classification, though corroborating evidence such as digital signature or handle analysis should still be reviewed.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.