GCFA Practice Question: Identification of Malicious and Normal Activity
Which log category should an analyst examine to identify a potential 'Pass-the-Hash' attack?
⚠ Common exam trap
Candidates mistakenly focus on generic login failures (4625) rather than successful logins (4624). Pass-the-Hash relies on valid authentication using a captured hash, so it appears as a successful logon event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security event logs for Event ID 4624.
Pass-the-Hash attacks involve an attacker using an NTLM hash to authenticate as a user without the cleartext password. This typically manifests in the Security event log during the authentication process. By looking for specific logon types and unusual source-to-destination authentication flows, analysts can detect when a hash has been reused across the network, even if the attacker never obtained the actual password through brute force or phishing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System event logs for service failures.
Why it's wrong here
System event logs focus on service status, hardware, and OS health. Authentication events, which are the core of a Pass-the-Hash attack, are recorded in the Security event logs. Searching the System logs would be ineffective as they do not capture the identity-based logon events required to detect hash reuse.
- ✓
Security event logs for Event ID 4624.
Why this is correct
Event ID 4624 captures successful logons. During a Pass-the-Hash attack, the analyst looks for anomalous authentication patterns, such as the use of NTLM for logons that should be Kerberos, or logins occurring from systems that do not usually communicate with the target, indicating the reuse of intercepted hashes.
- ✗
Application event logs for crash dumps.
Why it's wrong here
Application logs store events related to installed software and their operational errors. They do not record authentication or logon sessions. Pass-the-Hash is an identity-based exploit, and looking in the Application logs would yield no relevant evidence regarding the unauthorized authentication session or the hijacked user account.
- ✗
DNS query logs from the domain controller.
Why it's wrong here
DNS query logs track hostname resolution. While attackers might use DNS to find targets, this does not reveal the authentication process itself. The actual evidence of the Pass-the-Hash attack exists in the logs that record the session establishment, which are found in the Security event log.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.