Practice Exam 1
5 of this form’s 82 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
Enterprise Incident ResponseAn analyst reviewing a compromised jump host finds many type 9 logons for a service account. What does that logon type indicate about the session?
Question 2 of 5
Volatile Windows Artifacts and Malware AnalysisAn analyst wants the actual text of the commands a PowerShell session ran on a live host. Which logging feature records that content?
Question 3 of 5
File System Timeline ForensicsAn examiner compares a suspect document's internal properties with its file system times and finds a value the file system never records. Which value is that?
Question 4 of 5
NTFS and Windows Artifact AnalysisAn examiner reviewing an evidence image finds a folder whose discretionary access control list holds no access control entries. What effective access did that folder grant?
Question 5 of 5
Normal and Malicious Activity IdentificationAn analyst reviewing a workstation timeline sees Group Policy extensions running at every boot and at each user logon. Which routine mechanism does that repeating pattern describe?
0 of 82 completed
The other 77 questions are the rest of this form: same 180 minute clock, same 71 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 2 on GCFA.
What this exam covers
- Enterprise Incident Response12 questions / 15% of the exam
- Memory Forensics8 questions / 10% of the exam
- Volatile Windows Artifacts and Malware Analysis17 questions / 20% of the exam
- File System Timeline Forensics17 questions / 20% of the exam
- NTFS and Windows Artifact Analysis16 questions / 20% of the exam
- Normal and Malicious Activity Identification12 questions / 15% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.