GCFA Enterprise Environment Incident Response • Set 2
GCFA Enterprise Environment Incident Response Practice Test 2 — 15 questions with explanations. Free, no signup.
An enterprise incident response team is preparing to acquire volatile evidence from a compromised Windows server. The server is running critical business applications, and management wants to minimize downtime. Which TWO of the following actions should the team perform to properly capture volatile data while preserving system integrity? (Choose two.)
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.