Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?

⚠ Common exam trap

The trap here is focusing on the account name or SID to judge legitimacy; the same account can be used legitimately or maliciously, so the authentication method fields are what differentiate the two.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Logon Process and Authentication Package fields in the 4624 event

For a Logon Type 3 event, the Logon Process and Authentication Package fields reveal the mechanism used. A service account authenticating via its normal service process and package looks routine; the same account authenticating with an unexpected package or from an unusual logon process suggests credential theft and lateral movement. The other fields support correlation but do not distinguish method as directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Security ID (SID) of the account in the 4624 event

    Why it's wrong here

    The SID identifies the account and confirms it is the domain service account in question. While important for attribution, it does not reveal how the authentication occurred or whether the method was consistent with normal service activity, so it does not resolve the legitimate-versus-malicious question.

  • ✓

    The Logon Process and Authentication Package fields in the 4624 event

    Why this is correct

    The Logon Process and Authentication Package fields distinguish a network logon initiated by a service (for example, NTLM or Kerberos via a service host) from an interactive or explicit credential use. A mismatch, such as an unexpected authentication package or logon process for that account, is a strong indicator of credential misuse for lateral movement rather than normal service behavior.

  • ✗

    The Logon GUID field in the 4624 event

    Why it's wrong here

    The Logon GUID is a unique identifier that can correlate a logon session with other events, which is useful for tracking a session across the log. However, it does not by itself indicate whether the authentication was legitimate or malicious, so it is not the most critical detail for the initial triage decision.

  • ✗

    The Process ID and Process Name fields in the 4624 event

    Why it's wrong here

    The Process ID and Process Name fields identify the local process that initiated the logon. For a Logon Type 3 network logon, these often point to a system process such as lsass.exe and provide limited distinction between legitimate and malicious remote authentication, so they are less decisive than the authentication package and logon process.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.