Courseiva

GCFA Enterprise Environment Incident Response Practice Question

When investigating a suspected data exfiltration incident, which TWO sources are most useful for determining the volume and destination of the transferred data?

⚠ Common exam trap

Candidates often select host-based logs like file access or process execution logs, which track local activity but fail to provide the external destination IP and total bytes transferred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Network flow (NetFlow) logs.

Firewall logs and NetFlow data are the most reliable sources for quantifying data exfiltration. Firewall logs provide information about the connections made, while NetFlow provides the volume of data transferred between specific source and destination IPs. By analyzing these, an analyst can pinpoint the exact amount of data that left the network and where it was sent, which is crucial for reporting the incident's impact and determining the nature of the breached data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Application performance monitoring (APM) logs.

    Why it's wrong here

    APM logs track how software applications perform, focusing on metrics like latency, request rate, and error rates. They do not capture the raw network traffic data needed to calculate total bytes exfiltrated to an external destination, making them an ineffective source for determining the volume or destination of exfiltrated data.

  • ✓

    Network flow (NetFlow) logs.

    Why this is correct

    NetFlow provides a detailed record of network traffic, including source and destination IP addresses, ports, and, most importantly, the byte count for each flow. This makes it an ideal source for calculating the exact volume of data exfiltrated and identifying where that traffic was directed across the network boundary.

  • ✗

    Endpoint antivirus event logs.

    Why it's wrong here

    Antivirus logs track malware detections, blocked files, and scan results. They do not record network traffic volume or destination metadata for successful connections. Therefore, they are useful for identifying the malware involved but useless for quantifying the amount of data that was actually exfiltrated during the incident.

  • ✓

    Firewall connection logs.

    Why this is correct

    Firewall logs act as the primary record for all traffic traversing the network perimeter. They identify which internal hosts established connections to external IP addresses, when those connections occurred, and whether the traffic was allowed or denied, which is essential for confirming the destination and timing of an exfiltration attempt.

  • ✗

    Active Directory authentication logs.

    Why it's wrong here

    AD logs track user logins, account lockouts, and permission changes. While useful for identifying how an attacker may have gained access, they provide no information regarding network activity or the volume of data transferred out of the network, as they are strictly focused on identity and access management events.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.