Free practice test
GCFAFree GIAC Certified Forensic Analyst (GCFA) practice test
10 original GCFA questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.
Sample question 1 of 10
An analyst reads a 4697 service installation record on a running server and asks whether the binary path it shows is still the current one. What holds?
Sample question 2 of 10
A user says a file was sent to the Recycle Bin four months ago, but an analyst finds no trace of it there. What best explains the absence?
Sample question 3 of 10
An analyst sees a 4 GB file on an NTFS volume that reports only 12 MB of allocated space and carries no compression attribute. What accounts for the gap?
Sample question 4 of 10
An analyst reviewing file server logs during a breach sees repeated authenticated connections to C$ and ADMIN$ from a workstation. What are those shares?
Sample question 5 of 10
An analyst reviewing a workstation timeline sees Group Policy extensions running at every boot and at each user logon. Which routine mechanism does that repeating pattern describe?
Sample question 6 of 10
In a memory image, an analyst sees a library path written into the address space of a signed process and a new thread started on that library. Which technique fits?
Sample question 7 of 10
Process command lines on a compromised host show net group /domain and Get-ADGroupMember run minutes apart. Which adversary objective does that pair serve?
Sample question 8 of 10
An analyst reconciling a Windows event record against file activity sees two stored times on the record itself. Which one marks when the entry was submitted?
Sample question 9 of 10
An analyst finds a user profile folder whose creation time predates the incident by two days. What event normally creates that folder on a Windows host?
Sample question 10 of 10
An analyst finds ntds.dit and a copy of the SYSTEM hive in a staging folder on a domain controller. Which adversary behaviour does that pair indicate?
Full GCFA question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
What this test covers
These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Volatile Windows Artifacts and Malware Analysis, File System Timeline Forensics, NTFS and Windows Artifact Analysis, Enterprise Incident Response, Normal and Malicious Activity Identification, Memory Forensics. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.
A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 82 questions apportioned to the official domain weightings, sat under the real 180-minute clock and scored against the published cut score.
Keep reading
GCFA practice questions
Free sample questions with the full explanation on every answer.
GCFA passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is GCFA?
An honest difficulty read from the format, the clock and the weights.