GSEC · domain
Windows Forensics
This domain covers Windows forensic artifacts: registry hives, event logs, prefetch, and memory analysis. You must interpret evidence from a compromised host, such as logon types, program execution, and volatile data, to reconstruct attacker activity. Questions present exhibits and ask for the purpose or significance of specific artifacts.
Focused practice
Practice Windows Forensics questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Windows Forensics
A candidate must be able to identify and interpret Windows forensic artifacts from registry, event logs, prefetch, and memory. The most important thing is to correctly match artifacts to their forensic significance, such as Event ID 4624 for network logons or Prefetch hash for execution evidence.
Interpreting registry keys like Run, UserAssist, and USBSTOR for persistence and user activity.
Identifying Event IDs for logon types, such as 4624 for successful network logon (Type 3).
Explaining Prefetch file naming, including the hash appended to the executable name.
Collecting volatile data from memory when an executable is no longer on disk.
Watch out for
Common Windows Forensics exam traps
- ▸Confusing Event ID 4624 (successful logon) with 4625 (failed logon) or misidentifying logon types.
- ▸Assuming Prefetch hash is a malware signature rather than a path or volume identifier.
- ▸Overlooking registry artifacts that show execution or persistence, such as UserAssist or Run keys.
Question index
All Windows Forensics questions (11)
Click any question to see the full explanation, or start a practice session above.
During a forensic examination, you find a Prefetch file named 'MALWARE.EXE-A1B2C3D4.pf'. What is the significance of the hexadecimal string appended to the filename?
Medium2An incident responder needs to determine the last time a specific user interacted with a Windows workstation. Which registry hive should be analyzed to retrieve the LastWrite time of the user's NTUSER.DAT file?
Medium3An analyst is examining a Windows 10 host suspected of being used to stage and exfiltrate data. The analyst wants to identify evidence of files that were recently opened or created by the user, and of USB mass storage devices that were previously connected. Which two artifacts should the analyst examine to address these goals? (Choose two.)
Medium4An examiner is reviewing a Windows 11 workstation seized during an insider-threat investigation. The suspect denies ever connecting removable media, but the examiner finds a file named 'E01' inside 'C:\Windows\INF\' with no corresponding setupapi.dev.log entries for USB devices. Which artifact should the examiner correlate to confirm the specific USB storage device that was connected and its serial number?
Hard5Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?
Hard6An incident responder is analyzing a Windows 10 workstation that is suspected of being used to exfiltrate data. The responder runs 'wevtutil qe Security /q:"*[System[(EventID=5156)]]" /f:text' but finds no events. Which action will most reliably produce the network connection telemetry the responder needs for this investigation?
Medium7An examiner is analyzing a Windows 10 endpoint and finds that the user account was deleted before acquisition, but the examiner still needs to determine which files that user recently opened from a network share. The user's profile folder was also removed. Which artifact is most likely to retain this information?
Hard8A forensic examiner is reviewing an NTFS volume from a Windows 11 laptop. The user claims a sensitive spreadsheet was only opened and never modified or renamed. The examiner notes that the $STANDARD_INFORMATION timestamps for the file are all recent, but the $FILE_NAME timestamps are from several months earlier. Which explanation best accounts for this discrepancy?
Hard9Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?
Medium10An incident responder collects volatile data from a compromised Windows 10 workstation before pulling the power. The attacker used a custom executable that is no longer present on disk, but the responder needs to confirm which process spawned it and what child processes it created. Which artifact should the responder examine to establish this parent-child process relationship?
Medium11When investigating a Windows system, which file system feature is responsible for recording the file metadata including timestamps for created, modified, and accessed (MACE) times?
MediumOther domains
All GSEC exam domains
Frequently asked questions
- What does the Windows Forensics domain cover on the GSEC exam?
- A candidate must be able to identify and interpret Windows forensic artifacts from registry, event logs, prefetch, and memory. The most important thing is to correctly match artifacts to their forensic significance, such as Event ID 4624 for network logons or Prefetch hash for execution evidence.
- How many questions are in this domain?
- This page lists all 11 Windows Forensics questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Windows Forensics questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.