GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts
Exhibit
Refer to the exhibit: { 'EventID': 4688, 'ProcessName': 'powershell.exe', 'CommandLine': 'powershell.exe -enc JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAnAEgA... )' }Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?
⚠ Common exam trap
Candidates often assume running a static file analysis or searching for malicious domain names directly on the exhibit is sufficient, forgetting that '-enc' demands immediate decoding of the obfuscated PowerShell script before any other progress.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decode the base64 string and perform script analysis
The command line uses the '-enc' parameter, indicating a base64-encoded PowerShell script. Forensic analysts must decode this string to understand the attacker's intent. Once decoded, the analyst can identify the actual commands being run—such as downloading additional payloads or communicating with C2 servers. This is critical in modern incident response because obfuscation is a routine tactic to evade basic keyword-based monitoring and initial detection by security analysts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Search for the process name in the Shimcache
Why it's wrong here
Shimcache only records that the process was executed. It does not capture the command-line arguments or the encoded payload. Searching the Shimcache will confirm execution but will not provide the visibility needed to understand what the script was actually doing or what malicious actions were performed during the execution.
- ✓
Decode the base64 string and perform script analysis
Why this is correct
Decoding the base64 string is the only way to reveal the underlying PowerShell script executed by the attacker. This allows the analyst to see the actual commands, identify the targeted actions, and determine the scope of the incident, which is essential for creating an effective remediation plan for the compromised host.
- ✗
Check the MFT for the parent process file
Why it's wrong here
The parent process's file system metadata in the MFT does not provide the execution context or the command-line arguments. While file system forensics is useful for finding the binary, it cannot reveal the dynamic runtime instructions that were passed into the PowerShell engine during the suspected malicious activity.
- ✗
Run a system file integrity check
Why it's wrong here
A file integrity check like SFC would only verify that the legitimate powershell.exe binary has not been tampered with. It does not provide any context about the commands being executed within a PowerShell session. The malicious activity here is the script logic, not an alteration of the PowerShell binary itself.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.