Free practice test

GCFA

Free GIAC Certified Forensic Analyst (GCFA) practice test

10 original GCFA questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.

Sample question 1 of 10

Volatile Windows Artifacts and Malware Analysis

An analyst reads a 4697 service installation record on a running server and asks whether the binary path it shows is still the current one. What holds?

Sample question 2 of 10

File System Timeline Forensics

A user says a file was sent to the Recycle Bin four months ago, but an analyst finds no trace of it there. What best explains the absence?

Sample question 3 of 10

NTFS and Windows Artifact Analysis

An analyst sees a 4 GB file on an NTFS volume that reports only 12 MB of allocated space and carries no compression attribute. What accounts for the gap?

Sample question 4 of 10

Enterprise Incident Response

An analyst reviewing file server logs during a breach sees repeated authenticated connections to C$ and ADMIN$ from a workstation. What are those shares?

Sample question 5 of 10

Normal and Malicious Activity Identification

An analyst reviewing a workstation timeline sees Group Policy extensions running at every boot and at each user logon. Which routine mechanism does that repeating pattern describe?

Sample question 6 of 10

Memory Forensics

In a memory image, an analyst sees a library path written into the address space of a signed process and a new thread started on that library. Which technique fits?

Sample question 7 of 10

Volatile Windows Artifacts and Malware Analysis

Process command lines on a compromised host show net group /domain and Get-ADGroupMember run minutes apart. Which adversary objective does that pair serve?

Sample question 8 of 10

File System Timeline Forensics

An analyst reconciling a Windows event record against file activity sees two stored times on the record itself. Which one marks when the entry was submitted?

Sample question 9 of 10

NTFS and Windows Artifact Analysis

An analyst finds a user profile folder whose creation time predates the incident by two days. What event normally creates that folder on a Windows host?

Sample question 10 of 10

Normal and Malicious Activity Identification

An analyst finds ntds.dit and a copy of the SYSTEM hive in a staging folder on a domain controller. Which adversary behaviour does that pair indicate?

Full GCFA question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Volatile Windows Artifacts and Malware Analysis, File System Timeline Forensics, NTFS and Windows Artifact Analysis, Enterprise Incident Response, Normal and Malicious Activity Identification, Memory Forensics. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 82 questions apportioned to the official domain weightings, sat under the real 180-minute clock and scored against the published cut score.

Keep reading

Every guide and cost breakdown, by vendor