GCFA Practice Question: Identification of Malicious and Normal Activity
Which log artifact provides the most reliable evidence that a user account was used for an interactive remote login rather than a scheduled task?
⚠ Common exam trap
Examinees often confuse interactive remote RDP sessions (Logon Type 10) with standard local interactive logins (Logon Type 2) or network services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 4624 with Logon Type 10.
The Windows Security Event log captures specific Logon Types that categorize the nature of the authentication. Logon Type 2 denotes an interactive local login, while Type 10 identifies Remote Interactive (RDP) sessions. Scheduled tasks typically utilize Type 4 (Batch) or Type 5 (Service), allowing analysts to differentiate between user-driven activity and automated system processes through forensic inspection of the event data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Event ID 4624 with Logon Type 10.
Why this is correct
Logon Type 10 is the specific identifier for Remote Interactive logins, typically associated with RDP connections. This is the primary forensic artifact used to distinguish human-driven remote access from automated system tasks or background service authentication, which use different logon types within the Windows event auditing subsystem.
- ✗
Event ID 4672 during the authentication process.
Why it's wrong here
Event ID 4672 indicates special privileges assigned to a new logon session. While it often accompanies logins, it is not exclusive to remote interactive sessions and can occur with batch jobs or services if the account has elevated rights, making it an unreliable indicator for session type.
- ✗
Event ID 4648 involving the use of explicit credentials.
Why it's wrong here
Event ID 4648 signifies that a logon was attempted using explicit credentials, such as a user running a program as a different user. This does not confirm the session is interactive, as it often occurs during administrative script execution or service account management operations.
- ✗
Event ID 4720 occurring at the same time.
Why it's wrong here
Event ID 4720 tracks the creation of a user account. This event is entirely unrelated to authentication sessions or logon types. Using this as an indicator would lead to incorrect conclusions, as it documents identity management rather than the active session behaviors needed for incident response.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.