GCFA Practice Question: Identification of Malicious and Normal Activity
During an investigation of a Windows Server 2019 host, you review the Security event log and find Event ID 4624 entries with Logon Type 3 originating from a workstation subnet that should never authenticate to this server. The associated 4672 entry shows SeDebugPrivilege assigned to the resulting token. The account name is a normal helpdesk user. Which conclusion is most defensible from these artifacts alone?
⚠ Common exam trap
The trap here is assuming any 4672 event means the account is an administrator, when 4672 only shows privileges were assigned to the logon token, and the logon type still governs how the session began.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The helpdesk account authenticated over the network and received administrator-level privileges in that session.
A Logon Type 3 combined with Event 4672 indicates a network authentication that received special privileges, which is the classic signature of remote administrative access using a nominally low-privilege account. The unauthorized source subnet makes this more suspicious rather than less. Investigators should follow the source IP back to the originating host and check for credential theft or lateral movement tooling there.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The server was rebooted and the helpdesk account was used as a service account during startup.
Why it's wrong here
Service account logons produce Logon Type 5 and are tied to the Service Control Manager, with Event ID 7036 entries in the System log. A reboot would also generate Event IDs 6005, 6006, and 6008. The stem contains no reboot indicators, and Type 3 does not describe service startup. Attributing the activity to a reboot misreads the logon type and invents context not present in the evidence.
- ✓
The helpdesk account authenticated over the network and received administrator-level privileges in that session.
Why this is correct
Logon Type 3 confirms a network authentication (SMB, WMI, or similar), and Event 4672 is logged when a logon is assigned special privileges, here SeDebugPrivilege. The combination of an unexpected source subnet, a non-admin account name, and administrator-equivalent privileges indicates the account is being used with elevated rights from an unauthorized location, which warrants pivoting to the source host for further evidence.
- ✗
The helpdesk account performed an interactive RDP session to the server from the workstation subnet.
Why it's wrong here
Logon Type 3 is a network logon, not an interactive session. Type 10 is used for RDP, and Type 2 for local console. Seeing Type 3 with a helpdesk account does not support an RDP claim, and the 4672 entry alone does not convert a network logon into an interactive one. The scenario explicitly states the subnet should not authenticate, so RDP from that subnet would itself be anomalous, but the logon type contradicts the RDP interpretation.
- ✗
The account was used to start a scheduled task on the server, which explains the privileged token.
Why it's wrong here
Scheduled task execution typically produces Logon Type 4 (batch) or Type 5 (service) entries and is accompanied by Task Scheduler operational logs (Event IDs 106, 200, 201). Nothing in the stem references Task Scheduler activity, and Logon Type 3 does not match batch execution. The 4672 entry is consistent with any logon type, so it cannot by itself be attributed to a scheduled task.
Visual reference
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.