Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

Which forensic artifact is most useful for determining if a user has recently opened a specific suspicious file, even if that file has since been deleted?

⚠ Common exam trap

Candidates often confuse LNK files with registry keys or general prefetch files, failing to recognize that shell items specifically track direct user interactions and file paths even after target deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows LNK files and Jump Lists.

Shell items, specifically LNK files and Jump Lists, maintain metadata about user file interactions. When a user opens a file, the OS creates these artifacts, which persist even if the target file is removed. This makes them essential for identifying user intent and proving that a malicious file was not only present but was actively accessed by the user, providing critical evidence for attribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Windows Registry SAM hive.

    Why it's wrong here

    The SAM hive contains local user account information and password hashes. It does not track file access history or user interaction with specific files. Using the SAM hive to look for file usage is an ineffective approach as it serves a completely different function in Windows forensic analysis.

  • ✓

    Windows LNK files and Jump Lists.

    Why this is correct

    LNK files and Jump Lists are specifically designed to track recent user activity. They record the path, access time, and volume information for files opened by the user. These artifacts remain on the system after the source file is deleted, making them invaluable for reconstructing past user behavior during an investigation.

  • ✗

    System event logs (Event ID 7045).

    Why it's wrong here

    Event ID 7045 is generated when a new service is installed on the system. While useful for detecting persistence mechanisms, it provides no information about individual user file access. Relying on this for file tracking will lead to missing evidence regarding what files were opened by the user.

  • ✗

    The browser cache database.

    Why it's wrong here

    The browser cache tracks web-based activity and downloads. It does not track files opened locally via the Windows file system. If a malicious file was delivered via email or USB, the browser cache would likely not contain the necessary metadata to confirm if the user interacted with the file locally.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.