GCFA Practice Question: Identification of Malicious and Normal Activity
You are reviewing a Windows Server 2019 Security event log and find Event ID 4624 with Logon Type 3 and the 'NTLM' authentication package for a service account, occurring at 02:14 from a workstation that has no corresponding 4648 or 4672 events. Which interpretation is most forensically sound?
⚠ Common exam trap
The trap here is treating Logon Type 3 with NTLM as automatic proof of Pass-the-Hash, when it is only a network authentication that requires corroborating evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
This is a network logon using NTLM that warrants correlation with source host and account baseline.
Logon Type 3 identifies a network logon, and the NTLM authentication package means the session did not use Kerberos. That alone is not proof of compromise, but it is a meaningful indicator that must be baselined against the account's normal source hosts, logon patterns, and downstream privilege events before any conclusion about credential theft or lateral movement is drawn.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
This is normal service account behavior and no further review is needed.
Why it's wrong here
Treating a Type 3 NTLM logon from an unexpected workstation as benign ignores the context that the source host has no administrative purpose and the logon lacks the token elevation events that legitimate service use would typically generate. A forensic analyst should not dismiss the record without correlating it against the account's baseline hosts, logon hours, and the absence of related privilege events.
- ✗
This proves credential theft via Pass-the-Hash against the service account.
Why it's wrong here
Pass-the-Hash produces a network logon with NTLM, but the logon type and package alone cannot prove credential theft. A valid NTLM authentication could equally come from a legitimate application, a scheduled task, or a misconfigured service. Concluding PtH requires additional evidence such as anomalous source hosts, unusual logon hours, and subsequent lateral movement or privilege events.
- ✓
This is a network logon using NTLM that warrants correlation with source host and account baseline.
Why this is correct
Logon Type 3 with the NTLM package means the credentials were presented over the network rather than interactively, and the absence of 4672 special-privilege assignment or 4648 explicit-credential use suggests a straightforward authenticated network access. Because NTLM bypasses Kerberos policy controls, the record must be correlated with the account's normal source hosts to determine whether the authentication is anomalous.
- ✗
This indicates a successful interactive console logon by an attacker.
Why it's wrong here
Logon Type 3 is a network logon, not an interactive one. Interactive console access is recorded as Logon Type 2, and remote interactive sessions over RDP are Logon Type 10. Confusing the logon type would lead the analyst to misattribute the access vector and potentially miss the true source of the authentication, which here is a network-based service request.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.