Courseiva
Windows Forensics →mediumMultiple Choice

GSEC Windows Forensics Practice Question

An incident responder collects volatile data from a compromised Windows 10 workstation before pulling the power. The attacker used a custom executable that is no longer present on disk, but the responder needs to confirm which process spawned it and what child processes it created. Which artifact should the responder examine to establish this parent-child process relationship?

⚠ Common exam trap

The trap here is assuming that any artifact showing an executable ran (Amcache, SRUM, Prefetch) also preserves the parent-child process relationships, when only process-creation telemetry such as Sysmon Event ID 1 does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Sysmon Event ID 1 records in the Microsoft-Windows-Sysmon/Operational log

Sysmon's Process Create event records the image, command line, hashes, and both parent process ID and parent image for every new process, which is exactly the data needed to reconstruct a process tree after the binary is gone. Other artifacts such as Amcache, $MFT, and SRUM may show that a file existed or ran but do not preserve runtime parent-child relationships.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SRUM database's Application Resource Usage table

    Why it's wrong here

    SRUM (System Resource Usage Monitor) tracks per-application network usage, CPU time, and foreground/background duration over time, stored in SRUDB.dat. While it can show that an application executed, it does not capture parent process IDs, parent image names, or child process creation. It therefore cannot establish the process tree the responder is trying to reconstruct from the volatile system.

  • ✓

    The Sysmon Event ID 1 records in the Microsoft-Windows-Sysmon/Operational log

    Why this is correct

    Sysmon Event ID 1 (Process Create) captures the image path, command line, hashes, parent process ID, and parent image for each new process. This directly documents which process spawned the attacker's executable and the children it created, even after the binary is deleted. It is the most reliable volatile artifact for reconstructing the parent-child relationship in this scenario.

  • ✗

    The $MFT entries for the volume where the executable ran

    Why it's wrong here

    The $MFT records file metadata such as standard information timestamps, size, and data runs for files that exist or once existed on an NTFS volume. It does not track process creation, parent-child relationships, or runtime execution context. Since the executable was already deleted and the question concerns process lineage, the master file table cannot answer the responder's question.

  • ✗

    The Amcache.hve registry hive's Root\InventoryApplicationFile key

    Why it's wrong here

    Amcache's InventoryApplicationFile entries record metadata about executables that existed on the system, such as path, size, and first-seen timestamps. It does not record runtime process relationships, so it cannot show which process spawned the attacker's executable or what children it created. It is useful for proving an executable was present, but it will not reconstruct the process tree the responder needs here.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.