Courseiva

GCFA · topic practice

Analyzing Volatile and Windows Event Artifacts practice questions

This GCFA domain covers live-response and post-mortem analysis of memory and Windows event logs. Candidates must interpret process metadata, detect injection and hollowing, map network connections to PIDs, and read Security logon events. Questions use exhibits, multi-select, and scenario stems requiring tool-output interpretation rather than recall alone.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Analyzing Volatile and Windows Event Artifacts

What the exam tests

What to know about Analyzing Volatile and Windows Event Artifacts

Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.

Interpreting process metadata from memory tools like Volatility and Rekall for anomalies

Detecting process hollowing and code injection via memory artifacts and thread inspection

Correlating network connections to process IDs using netstat, Volatility netscan, and handles

Reading Windows Security event IDs for logon type, account, and interactive session timing

Watch out for

Common Analyzing Volatile and Windows Event Artifacts exam traps

  • ▸Confusing parent-child process relationships with injected code; a legitimate parent can spawn a hollowed child, so verify image path and memory mapping.
  • ▸Treating every hidden or unlinked connection as malicious; terminated processes and kernel structures can leave stale entries that require corroboration.
  • ▸Misreading logon event IDs: 4624 is a logon, 4625 failure, 4634 logoff, and logon type 2 versus 10 changes the interpretation entirely.

Practice set

Analyzing Volatile and Windows Event Artifacts questions

20 questions · select your answer, then reveal the explanation

During a live response memory analysis, you identify a process running from the 'C:\Windows\Temp' directory that has an established network connection. Which artifact should be prioritized to determine the specific parent process that spawned this suspicious executable?

When analyzing Windows Event Logs for signs of credential dumping using LSASS access, which TWO Event IDs should an analyst primarily prioritize?

Which volatile artifact is best suited to determine if a specific user account was actively logged into the system at the time a memory image was captured?

Which Windows Event Log artifact is most reliable for determining the exact time a user account password was changed?

When investigating an incident involving RDP (Remote Desktop Protocol), which THREE artifacts should an analyst check to establish a timeline of remote access?

An analyst finds an entry in the 'SRUM' (System Resource Usage Monitor) for a process that communicated with a known malicious IP address. What is the main forensic advantage of using SRUM over standard network logs?

An incident responder acquires a volatile memory dump from a compromised Windows 10 endpoint using WinPmem. During triage, the analyst needs to locate active network connections associated with a suspicious process PID 2412. Which Volatility plugin provides the most direct analysis of active network sockets tied to specific process structures in Windows 10 memory?

Which TWO of the following Windows Event IDs are most commonly used to detect the clearing of event logs, a common technique employed by attackers to hide their tracks during the anti-forensics phase of an engagement?

An analyst discovers a suspicious process in memory that has no file on disk but shows 'Mapped' memory protections. What technique is likely being used, and which forensic artifact is best suited to validate the origin of this memory segment?

Which of the following describes the purpose of the 'Shimcache' (also known as AppCompatCache) artifact in a Windows forensic investigation?

When analyzing volatile memory, which structure contains the 'PEB' (Process Environment Block), and why is it significant to a forensic investigator?

An analyst is investigating a suspected credential dumping attack targeting LSASS. Which THREE of the following artifacts or log entries are most likely to provide evidence of this activity?

An analyst is reviewing the Windows Registry to determine the 'Last Access' time of a specific file. Which registry hive is most likely to contain information regarding the file's last modified or accessed time when interacting with the 'ShellBags' artifact?

An analyst is reviewing a Windows 10 memory image for evidence of a process that was terminated just before capture. The analyst needs to recover artifacts of the terminated process that may no longer appear in the active process list. Which TWO Volatility 3 plugins should the analyst use to find terminated or unlinked process objects and their associated network endpoints? (Choose two.)

An analyst is examining a Windows 10 system and finds that the Security event log contains an event ID 4688 for a process creation, but the 'Creator Process Name' field is blank. Which of the following best explains this observation?

An analyst is investigating a suspected malware infection on a Windows 10 endpoint. The analyst has obtained a memory image and wants to identify processes that may be masquerading as legitimate system processes. Which two of the following techniques should the analyst use to detect process masquerading in the memory image? (Choose two.)

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

Exhibit

Refer to the exhibit: Event ID 4624, Logon Type 3, Logon Process 'NtLmSsp', Key Length 0.

When investigating a suspected fileless malware infection, you identify an anomaly in the 'PowerShell' Operational log. Which event ID indicates the execution of a base64 encoded command string often used to obfuscate malicious scripts?

Which THREE items are critical to inspect when analyzing a memory dump for evidence of Process Hollowing or Injection?

Based on the process metadata provided in the exhibit, what is the most significant indicator that requires further investigation?

Exhibit

Refer to the exhibit: { 'Process': 'svchost.exe', 'PID': 1234, 'ParentPID': 567, 'Path': 'C:\\Windows\\System32\\', 'StartTime': '2023-10-01T10:00:00Z', 'CommandLine': 'C:\\Windows\\System32\\svchost.exe -k netsvcs' }

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Analyzing Volatile and Windows Event Artifacts sessions

Start a Analyzing Volatile and Windows Event Artifacts only practice session

Every question in these sessions is drawn from the Analyzing Volatile and Windows Event Artifacts domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Analyzing Volatile and Windows Event Artifacts?
Be able to take a memory image or Security log and identify suspicious processes, injected code, and network connections tied to PIDs, then map logon events to users. The single most important thing: confirm findings across multiple artifacts before calling activity malicious.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Analyzing Volatile and Windows Event Artifacts questions in a focused session?
Yes — the session launcher on this page draws every question from the Analyzing Volatile and Windows Event Artifacts domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.