GCFA › Enterprise Environment Incident Response
This GCFA domain covers incident response across enterprise networks and cloud services: triaging compromised Windows and Linux hosts, preserving volatile and non-volatile evidence, containing active threats without destroying data, and reconstructing adversary activity from logs and artifacts. Questions present realistic scenarios and ask you to choose the correct acquisition, containment, or analysis action.
GCFA Enterprise Environment Incident Response — All 61 Questions
Every question in this domain with answers and detailed explanations.