GCIH Incident Response and Cyber Investigation Practice Question
During a security incident, a GCIH analyst discovers that an attacker used PowerShell to download and execute a malicious script from a remote server. The analyst wants to determine the full command line and parent process of the PowerShell execution to understand the attack vector. Which Windows artifact should the analyst examine to retrieve this information?
⚠ Common exam trap
The trap here is assuming that PowerShell script block logging captures the command line and parent process, when it only captures script content.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sysmon event ID 1 (Process Create)
Sysmon event ID 1 provides comprehensive process creation data, including the full command line and parent process, which are critical for understanding how PowerShell was invoked and what it executed. Other logs either lack command-line detail (Security 4688 by default) or focus on script content (PowerShell 4104) rather than process lineage. Thus, Sysmon is the most appropriate artifact to retrieve the required information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PowerShell operational log, event ID 4104
Why it's wrong here
Event ID 4104 in the PowerShell operational log records script block logging, which captures the content of scripts executed. While it can reveal the malicious script's code, it does not provide the full command line used to invoke PowerShell or the parent process information. Therefore, it is not the best source for understanding how PowerShell was launched.
- ✗
Windows System event log, event ID 7045
Why it's wrong here
Event ID 7045 in the System log records service installation. It is useful for detecting new services, but it does not capture process creation details like command lines or parent processes. In this scenario, the attacker used PowerShell, not a service, so this log is irrelevant to the investigation.
- ✗
Windows Security event log, event ID 4688
Why it's wrong here
Event ID 4688 logs process creation, but by default it does not include the full command line unless audit policy is configured to enable command line logging. Even then, it may not capture the parent process command line. In many environments, this setting is disabled, so relying solely on 4688 may not provide the required details for this scenario.
- ✓
Sysmon event ID 1 (Process Create)
Why this is correct
Sysmon event ID 1 logs process creation and includes rich details such as the full command line, parent process ID, user account, and hashes. This directly answers the analyst's need to see the exact PowerShell command line and its parent process, enabling reconstruction of the attack chain. Sysmon is commonly used in incident response for this level of detail.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.