Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

During an intrusion investigation on a Windows 10 workstation, an analyst observes that several user-mode processes have established TCP connections to 203.0.113.45:443. The analyst wants to determine which executable image on disk was responsible for the network activity and whether the process is still running. Which artifact provides the most direct evidence by mapping a live network connection to its owning process executable path?

⚠ Common exam trap

The trap here is assuming that any log showing a connection to the suspicious IP automatically identifies the responsible executable, when in fact only artifacts that include the process image path provide that attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sysmon Event ID 3 (Network connection detected) with the Image and DestinationIp fields

Sysmon Event ID 3 is specifically designed to log network connection events and includes the full image path of the process that initiated the connection, along with source and destination IP/port. This allows an analyst to definitively map a connection to an executable on disk and determine if that process was running at the time of the event. Other artifacts either lack process attribution, are non-persistent, or do not record the executable path in a usable form for this correlation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security event log 5156 (Windows Filtering Platform permitted a connection) filtered by destination IP

    Why it's wrong here

    Event 5156 records that the Windows Filtering Platform permitted a connection and includes an Application field, but it is extremely high-volume and often disabled by default; it also references the application by path only in some configurations and does not by itself confirm the process was still running or which command line was used. It is less direct than Sysmon Event ID 3 for linking a live connection to its executable.

  • ✓

    Sysmon Event ID 3 (Network connection detected) with the Image and DestinationIp fields

    Why this is correct

    Sysmon Event ID 3 records network connection events and includes the Image field (full path of the process executable) along with source/destination IP and port. This directly answers which executable initiated the connection to 203.0.113.45:443. If configured with adequate filtering, it captures this even when the process is short-lived, making it the most direct artifact for correlating a connection with an on-disk executable.

  • ✗

    Windows Firewall log entries recording allowed outbound connections to the remote IP

    Why it's wrong here

    The Windows Firewall log records allowed and dropped packets with source/destination IP and port, but it does not include the process image path or PID. It can confirm connectivity occurred but cannot identify which executable on disk was responsible, so it fails to answer the core question of attributing the connection to a specific binary.

  • ✗

    Netstat output showing the PID and remote address, correlated with Task Manager

    Why it's wrong here

    Netstat with the PID can map a current connection to a process, but it is a point-in-time snapshot and does not persist. If the process has exited or the connection was short-lived, this evidence is gone. It also requires the analyst to be on the live system and does not provide a historical record, whereas Sysmon Event ID 3 stores the event for later forensic review.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.