Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During an enterprise incident, you discover that an attacker modified the Windows event log service to record only selected events, effectively hiding malicious activity. Which Windows artifact should you analyze first to determine what modifications were made to the logging configuration?

⚠ Common exam trap

The trap here is assuming that clearing the Security event log (event ID 1102) is the only way attackers tamper with logging, when in fact they often modify registry-based logging configuration to selectively suppress events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SYSTEM registry hive, specifically the EventLog service key.

The EventLog service configuration is stored in the SYSTEM registry hive, making it the definitive source for determining if an attacker altered logging settings. Other artifacts like event logs themselves or file system metadata may provide indirect clues, but they do not contain the configuration details needed to identify what was changed. Examining the SYSTEM hive allows responders to see exactly which logs were enabled or disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SYSTEM registry hive, specifically the EventLog service key.

    Why this is correct

    The EventLog service configuration, including which logs are enabled and their file paths, is stored in the SYSTEM registry hive under CurrentControlSet\Services\EventLog. Analyzing this key reveals if an attacker disabled logging or redirected log files. This is the authoritative source for logging configuration changes and should be examined early in the investigation to understand the scope of tampering.

  • ✗

    The NTFS $LogFile for the volume containing the event logs.

    Why it's wrong here

    The NTFS $LogFile records metadata transactions for file system operations, not the contents of registry keys or service configurations. While it could show that a registry hive file was modified, it does not reveal the specific changes to logging settings. It is not a practical source for determining what logging configuration changes were made during an incident.

  • ✗

    The Application event log for service control manager events.

    Why it's wrong here

    The Application log may contain service control manager events (e.g., event ID 7036) showing that the event log service started or stopped, but it does not show configuration changes such as which logs are enabled. Attackers who modify logging settings may not stop the service, so this log alone would not reveal the modifications. It is not the primary artifact for logging configuration.

  • ✗

    The Security event log (EVTX) for event ID 1102.

    Why it's wrong here

    Event ID 1102 indicates the audit log was cleared, not that logging configuration was modified. While it can indicate anti-forensic activity, it does not reveal changes to the logging service configuration itself. Examining only this event would miss registry-based modifications to the event log service and could lead to an incomplete understanding of what the attacker changed.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.