Courseiva

GCFA Enterprise Environment Incident Response Practice Question

Exhibit

C:\> netstat -ano | findstr "ESTABLISHED"
TCP 10.10.1.5:445 192.168.50.20:49152 ESTABLISHED 4
TCP 10.10.1.5:443 203.0.113.45:443 ESTABLISHED 4820

Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?

⚠ Common exam trap

Candidates often struggle to identify the correct PID when multiple connections are listed. They fail to distinguish between standard internal traffic and anomalous external traffic, choosing the wrong process for investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The process with PID 4820.

The exhibit shows two active connections. The first is a standard SMB connection, but the second, PID 4820, connects to an external IP on port 443. This is highly suspicious for a server that should not have direct outbound HTTPS communication to an unknown external host. Identifying the process associated with PID 4820 allows the analyst to trace the activity back to the binary responsible for the unauthorized external communication, which is a key indicator of C2 traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The process with PID 4.

    Why it's wrong here

    PID 4 in Windows represents the System process, which handles low-level tasks like kernel operations and file system access via SMB. While it may be involved in legitimate network shares, it is rarely the culprit for arbitrary outbound HTTPS traffic to unknown external internet-based IP addresses in this specific context.

  • ✓

    The process with PID 4820.

    Why this is correct

    PID 4820 is initiating an outbound connection to 203.0.113.45 on port 443. This behavior is characteristic of command-and-control (C2) traffic, where a compromised host reaches out to an external server. Investigating this process is the most logical step to identify the malicious payload and determine the extent of the compromise.

  • ✗

    The connection to 10.10.1.5.

    Why it's wrong here

    10.10.1.5 is the local host address in this context. Connections to the local host address are standard and expected behavior for internal services. Focusing on the local address does not provide actionable intelligence regarding the source of the potentially malicious external communication originating from the compromised server environment.

  • ✗

    The SMB connection on port 445.

    Why it's wrong here

    Port 445 is the standard port for Server Message Block (SMB) file sharing in Windows environments. While attackers use SMB for lateral movement, the existence of this connection alone does not confirm malicious activity without further analysis of the associated user account, source machine, and the timing of the connection.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.