Courseiva
← Back to GIAC Certified Forensic Analyst questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise GIAC Certified Forensic Analyst practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GCFA
exam code
GIAC
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GCFA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

An analyst is investigating a suspected credential dumping incident on a Windows Server 2016 domain controller. The analyst has acquired a memory image and the Windows event logs. Which TWO of the following artifacts would provide the most direct evidence that LSASS memory was accessed for credential theft? (Choose two.)

Question 2hardmulti select
Full question →

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Question 3hardmulti select
Full question →

A forensic analyst is examining a Windows 10 memory image and suspects that a process has injected code into another process. The analyst wants to identify injected code by examining memory regions within the target process. Which two Volatility 3 plugins are most appropriate for detecting and analyzing injected code in memory? (Choose two.)

Question 4hardmulti select
Full question →

An analyst is examining a memory image from a Windows 10 system that is suspected of being infected with malware that uses process hollowing. The analyst wants to identify processes that may have been hollowed. Which TWO of the following artifacts or techniques are most indicative of process hollowing? (Choose two.)

Question 5hardmulti select
Full question →

Which TWO of the following are considered reliable methods for detecting hidden processes in memory forensics?

Question 6mediummulti select
Full question →

An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)

Question 7hardmulti select
Full question →

A forensic analyst is triaging a Windows 10 endpoint that is suspected of being part of a botnet. The analyst has collected the Security, System, and Application event logs, the Sysmon operational log, and a live memory image. Which TWO of the following artifacts would provide the most direct evidence of periodic command-and-control beaconing behavior? (Choose two.)

Question 8hardmulti select
Full question →

During a memory forensics investigation of a Windows 10 image, you suspect an attacker injected code into a legitimate process. Which TWO Volatility 3 plugins would you use together to detect and characterize the injected code? (Choose two.)

Question 9hardmulti select
Full question →

Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?

Question 10mediummulti select
Full question →

Which THREE items are typically stored in a thread's TEB (Thread Environment Block)?

Question 11hardmulti select
Full question →

Which TWO of the following actions are considered 'anti-forensic' techniques that directly impact file system timeline analysis?

Question 12mediummulti select
Full question →

An analyst is preparing to acquire memory from a compromised server. Which TWO of the following factors are the most critical to consider regarding the integrity of the evidence and system stability?

Question 13mediummulti select
Full question →

During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)

Question 14mediummulti select
Full question →

An enterprise incident response team is preparing to conduct a forensic investigation on a compromised Linux server. The server is still running and cannot be taken offline. Which TWO of the following commands are appropriate for collecting volatile network connection information while minimizing disruption to the system? (Choose two.)

Question 15mediummulti select
Full question →

During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)

Question 16mediummulti select
Full question →

An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)

Question 17mediummulti select
Full question →

An analyst is reconstructing a suspected credential-dumping incident on a Windows 10 host and has already imaged memory. Which TWO artifacts should the analyst examine to determine whether the LSASS process memory was accessed by an unauthorized tool? (Choose two.)

Question 18hardmulti select
Full question →

An examiner is reviewing a Windows memory image for evidence of process hollowing. Which two artifacts, when observed together, most strongly support that a process has been hollowed? (Choose two.)

Question 19hardmulti select
Full question →

A forensic analyst is examining a memory image from a Windows 10 system suspected of having a rootkit that hides processes by unlinking them from the active process list. The analyst runs windows.pslist and windows.psscan to compare results. Which two of the following statements accurately describe the expected findings or implications? (Choose two.)

Question 20hardmulti select
Full question →

A forensic analyst is examining an NTFS volume and wants to identify potential timestomping. Which TWO artifacts should the analyst compare to detect inconsistencies in file timestamps? (Choose two.)

These GCFA practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GCFA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.