GCFA Enterprise Environment Incident Response Practice Question
During an incident response engagement, you need to establish a timeline of adversary activity on a compromised Windows server. Which data source is most appropriate for correlating user logon events, service installations, and process executions?
⚠ Common exam trap
The trap here is assuming that file system metadata orPrefetch alone can provide a complete timeline, when they only cover specific types of activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Event Logs
Windows Event Logs are the most comprehensive source for correlating diverse activities such as logons, service installations, and process executions. They provide a centralized, timestamped record that can be analyzed to reconstruct a timeline of adversary actions across the system, making them indispensable for incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Event Logs
Why this is correct
Windows Event Logs, particularly Security, System, and Application logs, record logon events, service installations, and process creation (with appropriate auditing). They provide timestamps and details necessary for building a comprehensive timeline of adversary activity across multiple event types.
- ✗
Registry hives
Why it's wrong here
Registry hives contain configuration data and some historical artifacts, but they do not provide a chronological log of events like logons or service installations. They might show persistence mechanisms, but correlating events across time requires a more event-centric source.
- ✗
Prefetch files
Why it's wrong here
Prefetch files only record execution of applications, not logon events or service installations. They can help identify executed programs but lack the breadth needed for a full timeline. They are also limited to a certain number of executions and may not persist for all activities.
- ✗
File system metadata (MAC times)
Why it's wrong here
File system metadata provides timestamps for file creation, modification, and access, but it does not capture logon events or service installations directly. It is useful for file-related activity but insufficient for a holistic timeline that includes user and service actions.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.