GCFA Windows Artifact Analysis Practice Question
During a compromise investigation, an analyst reviews Windows Event Logs and observes that Security Event ID 4688 entries are present, but the Process Command Line field is empty for all of them. The system is running Windows 10 Enterprise. What is the most likely reason for the missing command line data?
⚠ Common exam trap
The trap here is assuming that enabling process creation auditing automatically records command lines, when a separate policy must also be enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'Include command line in process creation events' policy under Administrative Templates\System\Audit Process Creation is not enabled.
The correct answer is the policy that controls command-line inclusion in process creation events. When enabled, it populates the Process Command Line field in Event ID 4688. Without it, the field remains empty. This is a common pitfall because process creation auditing alone does not guarantee command-line visibility; the separate policy must be turned on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security log has wrapped, and older entries containing command lines were overwritten before collection.
Why it's wrong here
Log wrapping would cause entire events to be lost, not blank fields within present events. The events are still recorded with all other fields, so overwriting is not the cause. The specific absence of command line data points to an audit policy configuration rather than log retention limits.
- ✓
The 'Include command line in process creation events' policy under Administrative Templates\System\Audit Process Creation is not enabled.
Why this is correct
This policy, when enabled, adds the full command line to the Process Creation event. Without it, Windows records the new process ID and image name but leaves the command line field blank. Enabling it requires a Group Policy update or registry change and is not on by default even when process creation auditing is active.
- ✗
The Windows Event Log service is configured to filter out command-line data for privacy reasons via a built-in security template.
Why it's wrong here
There is no built-in privacy filter that strips command-line data from Event ID 4688. Command-line inclusion is controlled explicitly by the audit policy setting. No default security template removes this field, and such behavior would be unusual and non-standard for Windows 10 Enterprise.
- ✗
Process creation auditing is not enabled at all, so Event ID 4688 should not appear.
Why it's wrong here
The scenario states that Event ID 4688 entries are present, which means process creation auditing is enabled. The issue is the missing command line within those events, not the absence of the events themselves. Disabling process creation auditing would remove the events entirely.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.