GCFA Windows Artifact Analysis Practice Question
During a forensic examination of a Windows 10 workstation, an analyst needs to determine which user account was interactively logged on at a specific date and time. The system is powered off and only the disk image is available. Which artifact should the analyst examine to find the most reliable record of interactive logon sessions, including logon type and timestamp?
⚠ Common exam trap
The trap here is assuming that any user activity artifact, such as shell bags or Prefetch, can substitute for explicit logon event records when determining interactive logon sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security event log, filtering for Event ID 4624 with Logon Type 2 or 10
Security event log entries with Event ID 4624 and Logon Type 2 or 10 provide definitive records of interactive and RemoteInteractive logons, including the account name, timestamp, and logon type. Other artifacts like shell bags, SRUM, or Prefetch may show user activity but lack the direct logon session details required to answer who was logged on and when.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prefetch files, checking the last execution time of explorer.exe
Why it's wrong here
Prefetch files record execution times of applications and can indicate when explorer.exe ran, but explorer.exe runs continuously during a session and does not map to a specific user logon. Prefetch does not contain user account information or logon type, so it cannot identify which user was logged on interactively at a given time.
- ✗
NTUSER.DAT registry hive, examining the LastWrite time of the user's shell bags
Why it's wrong here
Shell bags in NTUSER.DAT record folder view preferences and can suggest a user accessed certain folders, but they do not reliably record logon sessions or their timestamps. The LastWrite time of a shell bag key reflects when the view settings were last changed, not when the user logged on. This artifact cannot establish interactive logon times with the precision required.
- ✓
Security event log, filtering for Event ID 4624 with Logon Type 2 or 10
Why this is correct
Event ID 4624 in the Security log records successful logons and includes the Logon Type field. Type 2 indicates interactive logon at the console, while Type 10 indicates RemoteInteractive (RDP). These events provide the account name, timestamp, and logon type, directly answering who was logged on interactively and when, assuming the log has not been cleared or overwritten.
- ✗
SRUM database, querying the Network Usage table for active connections
Why it's wrong here
The System Resource Usage Monitor (SRUM) database tracks application resource usage and network data per user, but it does not record logon events or logon types. While SRUM can show user activity over time, it lacks the explicit logon session information and timestamps needed to determine who was interactively logged on at a specific moment.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.