GSEC Windows Forensics Practice Question
During a forensic examination, you find a Prefetch file named 'MALWARE.EXE-A1B2C3D4.pf'. What is the significance of the hexadecimal string appended to the filename?
⚠ Common exam trap
Candidates often mistakenly believe the hash represents the file content itself (like an MD5 or SHA256), missing that Prefetch hashes are specifically tied to the execution path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is a hash derived from the file's execution path.
Windows Prefetch files store metadata about application execution to speed up startup times. The hash appended to the filename is calculated based on the path from which the application was executed. This allows investigators to differentiate between multiple instances of the same binary running from different directories, which is a common technique used by attackers to hide malicious binaries in non-standard, obfuscated system locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It is a randomized identifier generated at system boot.
Why it's wrong here
The hash is not randomized; it is a deterministic calculation based on the file path. Randomized identifiers would prevent the operating system from consistently mapping the prefetch data to the correct application, rendering the performance enhancement feature ineffective and failing the requirement for stable application startup tracking.
- ✗
It represents the hash of the file's content.
Why it's wrong here
Prefetch hashes are derived from the execution path, not the actual file contents. If it were a file hash, the system would be unable to track executions of the same binary from different locations, which is critical for the intended performance optimization logic used by Windows.
- ✓
It is a hash derived from the file's execution path.
Why this is correct
The hash is calculated using the full path of the executable. This allows the system to store distinct prefetch information for applications sharing the same name but residing in different directories, providing forensic investigators with the exact location where the binary was executed from.
- ✗
It is the timestamp of the last execution.
Why it's wrong here
The filename does not contain a timestamp. The actual execution timestamps are stored within the binary data structure inside the Prefetch file itself, not in the filename. The filename structure relies exclusively on the path hash to ensure uniqueness for the Prefetch manager's internal mapping.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.