Courseiva

GCFA Practice Question: Identification of Malicious and Normal Activity

You are analyzing a system and find evidence that a user has executed a PowerShell script that imports the 'Net.WebClient' class. What is the most likely purpose of this script?

⚠ Common exam trap

Examinees sometimes misinterpret .NET class imports as benign software development activity instead of recognizing them as standard living-off-the-land download mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To download and execute a remote payload from a C2 server.

The 'Net.WebClient' class in .NET is frequently used in PowerShell to download remote content. In a forensic context, it is a hallmark of download-and-execute malware. Attackers use this to fetch secondary payloads from C2 servers. Identifying this class usage is critical for characterizing the scope of an attack, as it explains how the initial stub on the system was used to pull down more complex malicious tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To perform local file system encryption for data backup.

    Why it's wrong here

    Using 'Net.WebClient' is for network communication, not local file system manipulation. While backup tools may use network protocols, this class is specifically tailored for downloading objects from URIs. Linking it to local encryption is a misunderstanding of the class functionality and the purpose of .NET network libraries.

  • ✓

    To download and execute a remote payload from a C2 server.

    Why this is correct

    The 'Net.WebClient' class is the standard, built-in way for PowerShell scripts to perform HTTP or HTTPS GET/POST requests to download remote data. In incident response, the presence of this class in a script is a strong indicator of a download-and-execute operation used by attackers to pull secondary malicious payloads.

  • ✗

    To monitor the system for unauthorized network connections.

    Why it's wrong here

    While it can send data, 'Net.WebClient' is an initiator, not a passive monitoring tool. It does not provide the capability to monitor system network connections. Mistaking an active download tool for a passive security monitor is a common error that can lead to missing the true intent of a script.

  • ✗

    To clear the Windows Event Logs to hide tracks.

    Why it's wrong here

    Clearing logs is typically done using the 'Clear-EventLog' cmdlet or WMI commands, not by using the 'Net.WebClient' class. The WebClient class is meant for network communication, and associating it with log clearing demonstrates a lack of understanding of standard PowerShell administration and malicious activity patterns.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.