Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

During a live-response investigation of a Windows 10 workstation, you need to determine which user account was interactively logged on at the console at the exact moment of the incident. Which artifact provides the most direct evidence of the currently active interactive session?

⚠ Common exam trap

The trap here is assuming that the presence of a user profile hive such as NTUSER.DAT proves an active interactive session, when it only proves the profile was loaded at some point.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Security event log entry 4624 with Logon Type 2 recorded at the time of the incident

An interactive logon is recorded as Security event 4624 with Logon Type 2, which is generated when a user authenticates at the console. Because the question asks who was actively logged on at the moment of the incident, that specific logon type is the most direct and reliable evidence, whereas logoff entries and profile hives persist or indicate termination rather than active presence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Security event log entry 4624 with Logon Type 2 recorded at the time of the incident

    Why this is correct

    Event ID 4624 with Logon Type 2 indicates an interactive logon at the console, recorded in the Security log at the moment the session was established. In this scenario it directly ties a specific account to a physical or console session, making it the most reliable artifact for confirming who was actively logged in at the time of the incident.

  • ✗

    The NTUSER.DAT registry hive loaded in the user's profile folder

    Why it's wrong here

    NTUSER.DAT is loaded for any user profile that has been accessed, including via network logons or service accounts, and it persists after logoff. It does not record whether the session is currently interactive or which logon type was used, so it cannot reliably establish who was actively at the console during the incident.

  • ✗

    The Security event log entry 4634 recording a logoff event

    Why it's wrong here

    Event ID 4634 indicates that a logon session ended, not that one is active. Relying on a logoff entry would tell you a session terminated, which is the opposite of what is needed to confirm a currently active interactive session at the console during the incident window.

  • ✗

    The Security event log entry 4647 recording a user-initiated logoff

    Why it's wrong here

    Event ID 4647 is generated when a user initiates a logoff, meaning the session is ending. It does not confirm an active interactive session and would actually suggest the user was leaving the console, making it unsuitable for determining who was logged on at the moment of the incident.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.