GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
During an investigation of a compromised Windows host, you review the Security event log and find Event ID 4624 with Logon Type 3. The account name is a domain service account, and the source network address is an internal server. You need to determine whether this represents a legitimate service authentication or an attacker using the account for lateral movement. Which additional event log detail is most critical to examine?
⚠ Common exam trap
The trap here is focusing on the account name or SID to judge legitimacy; the same account can be used legitimately or maliciously, so the authentication method fields are what differentiate the two.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Logon Process and Authentication Package fields in the 4624 event
For a Logon Type 3 event, the Logon Process and Authentication Package fields reveal the mechanism used. A service account authenticating via its normal service process and package looks routine; the same account authenticating with an unexpected package or from an unusual logon process suggests credential theft and lateral movement. The other fields support correlation but do not distinguish method as directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security ID (SID) of the account in the 4624 event
Why it's wrong here
The SID identifies the account and confirms it is the domain service account in question. While important for attribution, it does not reveal how the authentication occurred or whether the method was consistent with normal service activity, so it does not resolve the legitimate-versus-malicious question.
- ✓
The Logon Process and Authentication Package fields in the 4624 event
Why this is correct
The Logon Process and Authentication Package fields distinguish a network logon initiated by a service (for example, NTLM or Kerberos via a service host) from an interactive or explicit credential use. A mismatch, such as an unexpected authentication package or logon process for that account, is a strong indicator of credential misuse for lateral movement rather than normal service behavior.
- ✗
The Logon GUID field in the 4624 event
Why it's wrong here
The Logon GUID is a unique identifier that can correlate a logon session with other events, which is useful for tracking a session across the log. However, it does not by itself indicate whether the authentication was legitimate or malicious, so it is not the most critical detail for the initial triage decision.
- ✗
The Process ID and Process Name fields in the 4624 event
Why it's wrong here
The Process ID and Process Name fields identify the local process that initiated the logon. For a Logon Type 3 network logon, these often point to a system process such as lsass.exe and provide limited distinction between legitimate and malicious remote authentication, so they are less decisive than the authentication package and logon process.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.