Courseiva
Windows Artifact Analysis →mediumMultiple Choice

GCFA Windows Artifact Analysis Practice Question

During an intrusion investigation, an analyst needs to determine the exact moment a malicious service was installed on a Windows 10 host. The attacker deleted the service's executable and cleared the System event log. Which artifact should the analyst examine to recover the service installation timestamp?

⚠ Common exam trap

The trap here is assuming that execution artifacts like Prefetch or Amcache can pinpoint service installation, when they actually indicate execution or file inventory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Registry key LastWrite time under HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>

The Services registry key maintains configuration data for each service, and its LastWrite time updates upon creation or modification. This artifact survives executable deletion and log clearing, offering a reliable timestamp for service installation. Other artifacts like SRUM, Prefetch, or Amcache provide execution or resource usage context but not the specific service registration time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SRUM (System Resource Usage Monitor) database

    Why it's wrong here

    SRUM tracks application resource consumption and network usage over time, storing data in ESE database format. While it can show that a process existed and consumed resources, it records usage intervals rather than service installation events. It does not capture the creation or modification timestamp of a service registration, and its retention is typically 30-60 days, making it unreliable for precise installation timing after log clearing.

  • ✓

    Registry key LastWrite time under HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>

    Why this is correct

    The Services registry key stores configuration for each installed service. When a service is created or modified, the LastWrite time of its subkey under CurrentControlSet\Services is updated. This timestamp persists even if the executable is deleted and event logs are cleared, providing a reliable forensic indicator of when the service was installed or last altered. Analysts can correlate this with other artifacts to confirm the installation time.

  • ✗

    Amcache.hve inventory entry for the service executable

    Why it's wrong here

    Amcache.hve stores metadata about executed or installed applications, including file paths and SHA-1 hashes, but it is primarily populated when a program is run or when the operating system inventories files. It does not record service installation events. If the service binary was deleted, Amcache may still contain an entry, but it reflects file presence or execution, not the precise moment the service was registered.

  • ✗

    Prefetch file for the service executable (e.g., SERVICENAME.EXE-XXXXXXXX.pf)

    Why it's wrong here

    Prefetch files record execution of applications, including the first and last run times, but they are created only when the executable runs. If the attacker deleted the service binary, the corresponding prefetch file may also be missing or deleted. Even if present, prefetch indicates execution, not installation. It does not directly reveal when the service was registered in the system, and its timestamps can be altered.

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.