Courseiva
← Back to GIAC Certified Forensic Analyst questions

Scenario-based practice

Hard Difficulty Questions

Practise GIAC Certified Forensic Analyst practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GCFA
exam code
GIAC
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GCFA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Question 2hardmulti select
Full question →

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Question 3hardmulti select
Full question →

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Question 4hardmultiple choice
Full question →

An incident responder is analyzing a memory image from a Windows 10 system that is suspected of being infected with a fileless malware. The responder runs the Volatility 3 windows.malfind plugin and observes several memory regions with PAGE_EXECUTE_READWRITE protection and a MZ header. However, the responder notices that some of these regions are backed by a file on disk, while others are not. Which of the following conclusions is most appropriate regarding the unbacked regions?

Question 5hardmultiple choice
Full question →

An analyst is examining a Windows 10 system and finds that the ShimCache (AppCompatCache) contains an entry for a malicious executable. The analyst wants to determine whether the executable was actually executed on the system. Which additional artifact should the analyst examine to confirm execution?

Question 6hardmultiple choice
Full question →

A forensic analyst is examining a memory dump from a Windows 10 system that is suspected of being infected with a rootkit that hides its presence by unlinking its process from the active process list. The analyst runs Volatility 3 and compares the output of the windows.pslist and windows.psscan plugins. Which of the following best describes the expected discrepancy between these two plugins in the presence of such a rootkit?

Question 7hardmulti select
Full question →

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Question 8hardmultiple choice
Full question →

When identifying a hidden process via a cross-view analysis, which memory structure is most reliable to compare against the EPROCESS list?

Question 9hardmultiple choice
Full question →

An investigator is analyzing a Windows system and notices that a file's $STANDARD_INFORMATION timestamps show a creation date of 2020, while the $FILE_NAME timestamps show a creation date of 2023. The file's content appears to be from 2023. The investigator suspects timestomping. Which NTFS artifact should be examined to corroborate the true creation time by looking at when the file's MFT record was last modified?

Question 10hardmulti select
Full question →

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Question 11hardmultiple choice
Full question →

An incident responder is building a MACB timeline from an ext4 file system using the Sleuth Kit. Why might the resulting timeline display execution timestamps or access times that appear unreliable for establishing user activity?

Question 12hardmultiple choice
Full question →

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

Exhibit

Exhibit C: Volatility malfind output
PID: 2456 | Address: 0x00A00000 | Tag: VadS | Protection: PAGE_EXECUTE_READWRITE
Header: MZ
Content: 4D 5A 90 00 ...
Question 13hardmultiple choice
Full question →

An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?

Question 14hardmultiple choice
Full question →

Why does the use of 'DKOM' (Direct Kernel Object Manipulation) by rootkits pose a significant challenge for traditional forensic tools that rely on the Windows API?

Question 15hardmulti select
Full question →

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Question 16hardmultiple choice
Full question →

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

Question 17hardmulti select
Full question →

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Question 18hardmulti select
Full question →

Which TWO of the following attributes in an NTFS MFT record are most critical for establishing the 'MACB' timeline of a file?

Question 19hardmultiple choice
Full question →

An analyst is examining an NTFS volume and finds that a file's $DATA attribute is resident. The file size is 800 bytes. The analyst attempts to recover the file content using a tool that only reads the data runs from the MFT record. What will be the outcome of this recovery attempt?

Question 20hardmultiple choice
Full question →

A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?

These GCFA practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GCFA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.