Courseiva

GCFA Practice Question: Analyzing Volatile and Windows Event Artifacts

Exhibit

Refer to the exhibit: Event ID 4624, Logon Type 3, Logon Process 'NtLmSsp', Key Length 0.

Which conclusion regarding this network logon event is most accurate based on the provided Windows Event Log details?

⚠ Common exam trap

Candidates often mistake a Logon Type 3 for a simple interactive login or misinterpret the NTLM key length as a successful encryption attempt rather than a indicator of legacy/weak protocols.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The authentication utilized NTLMv1 or failed to negotiate encryption

A Logon Type 3 indicates a network logon, typically associated with accessing a shared resource or remote service. The 'NtLmSsp' package signifies NTLM authentication, and the Key Length of 0 indicates that NTLMv1 is being used or encryption is absent. This suggests a legacy or potentially insecure authentication attempt, which is a common indicator of lateral movement using outdated protocols that are susceptible to relay attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user performed an interactive console logon

    Why it's wrong here

    Logon Type 2 represents an interactive logon at the local console. The exhibit clearly specifies Logon Type 3, which is reserved for network connections such as accessing a shared folder or a printer, not a direct physical or remote desktop console login performed by a user.

  • ✓

    The authentication utilized NTLMv1 or failed to negotiate encryption

    Why this is correct

    A key length of 0 in an NTLM authentication event is a strong indicator of NTLMv1 usage or a failure to negotiate session security. This is critical for forensic analysts because NTLMv1 is cryptographically weak, and its presence often signals that an attacker is attempting to downgrade the authentication protocol.

  • ✗

    The event represents a Kerberos ticket granting service request

    Why it's wrong here

    Kerberos authentication events are identified by the 'Kerberos' package name in the Logon Process field. The exhibit explicitly lists 'NtLmSsp', which is the security support provider for NTLM. Therefore, this event does not involve the Kerberos protocol, making it irrelevant to TGS or TGT ticket analysis.

  • ✗

    The account was locked out due to excessive attempts

    Why it's wrong here

    Event ID 4624 signifies a successful logon. Account lockouts are typically represented by Event ID 4740. A successful logon event does not provide information regarding account lockouts, as the authentication process completed successfully, granting the user access to the resource requested during this specific network session.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.