Practice Exam 2
5 of this form’s 82 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
Enterprise Incident ResponseAn analyst reviewing file server logs during a breach sees repeated authenticated connections to C$ and ADMIN$ from a workstation. What are those shares?
Question 2 of 5
Volatile Windows Artifacts and Malware AnalysisAn analyst reads a 4697 service installation record on a running server and asks whether the binary path it shows is still the current one. What holds?
Question 3 of 5
File System Timeline ForensicsA user says a file was sent to the Recycle Bin four months ago, but an analyst finds no trace of it there. What best explains the absence?
Question 4 of 5
NTFS and Windows Artifact AnalysisAn analyst sees a 4 GB file on an NTFS volume that reports only 12 MB of allocated space and carries no compression attribute. What accounts for the gap?
Question 5 of 5
Normal and Malicious Activity IdentificationWhile baselining a workstation, an analyst confirms a signed driver traces to a well known certificate authority. Which property does that chain of trust establish about the file?
0 of 82 completed
The other 77 questions are the rest of this form: same 180 minute clock, same 71 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 2 of 2 on GCFA.
What this exam covers
- Enterprise Incident Response12 questions / 15% of the exam
- Memory Forensics8 questions / 10% of the exam
- Volatile Windows Artifacts and Malware Analysis17 questions / 20% of the exam
- File System Timeline Forensics17 questions / 20% of the exam
- NTFS and Windows Artifact Analysis16 questions / 20% of the exam
- Normal and Malicious Activity Identification12 questions / 15% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.