GCFA Enterprise Environment Incident Response • Set 1
GCFA Enterprise Environment Incident Response Practice Test 1 — 15 questions with explanations. Free, no signup.
An incident responder identifies a suspicious PowerShell process executing encoded commands on an enterprise server. To effectively contain the host while preserving volatile evidence for forensic analysis, which action should the responder prioritize?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.