Courseiva

CHFI · domain

Incident Response and First Responder Skills

This domain covers the first responder's role on live Windows and Linux systems: securing the scene, volatile data order of volatility, and documenting actions. CHFI tests it through short scenarios where you pick the correct command, tool, or containment step and justify why it preserves evidence best.

15 questions5 easy6 medium4 hard

Focused practice

Practice Incident Response and First Responder Skills questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Incident Response and First Responder Skills

Be able to triage a live system: identify suspicious connections and processes, capture volatile data in the correct order, contain without destroying evidence, and document every action. The single most important thing is preserving volatile evidence before it is lost.

Running netstat -ano to map PIDs to suspicious outbound C2 connections on Windows

Capturing volatile data in order: memory, network connections, processes, then disk

Using trusted tools and write blockers so live response minimally alters evidence

Isolating a compromised host via network containment while keeping it powered for memory capture

Watch out for

Common Incident Response and First Responder Skills exam traps

  • ▸Pulling the plug or shutting down first, destroying volatile memory, network state, and running-process evidence that cannot be recovered later.
  • ▸Trusting attacker-controlled binaries on the compromised host instead of running commands and tools from verified, read-only external media.
  • ▸Confusing containment with eradication, or capturing disk before volatile data, violating the order of volatility.

Question index

All Incident Response and First Responder Skills questions (15)

Click any question to see the full explanation, or start a practice session above.

1

A security team suspects a data breach via an external attacker. The incident response plan requires preservation of evidence for legal proceedings. Which order of volatility should the first responder follow?

Medium
2

Refer to the exhibit. A first responder runs the netstat command on a compromised Windows workstation. Which of the following conclusions is BEST supported by the output?

Easy
3

You are responding to a suspected malware infection on a Windows 10 system. The system is still running. Which of the following should you collect FIRST?

Medium
4

A first responder arrives at a workstation suspected of being compromised by malware that is still running. The user is logged in and a suspicious process is active. The responder needs to capture volatile data before shutting down. Which command should be used first to capture the contents of RAM to a file?

Medium
5

An analyst receives an alert indicating a suspicious process (PID 3342) is making outbound connections on port 443 to an unknown IP. The system is a Windows 10 workstation. Which first responder action is MOST appropriate?

Easy
6

Refer to the exhibit. During incident response, a first responder runs 'netstat -ano' on a compromised Windows system. Which connection is most likely to be the command-and-control (C2) channel and should be prioritized for isolation?

Easy
7

During the initial response to a suspected data breach, a first responder discovers a live system with active network connections. The responder needs to preserve evidence while minimizing alteration. Which of the following is the MOST appropriate first step?

Medium
8

During incident response, a first responder discovers a compromised system with signs of an active command-and-control (C2) connection. What is the MOST important immediate action to preserve evidence and prevent further damage?

Medium
9

During an incident response, a first responder needs to collect volatile data from a compromised Windows 10 system. The system has PowerShell v5.1 available. Which PowerShell cmdlet should be used to capture a list of currently running processes with their associated command lines?

Hard
10

A first responder is called to a scene where a Windows laptop is suspected of being used in a crime. The laptop is turned on and logged in. The responder needs to preserve the most volatile evidence first. Which of the following should be captured first?

Easy
11

A first responder is called to investigate a potential insider threat. The suspect's computer is turned off. What is the BEST procedure?

Easy
12

During the initial response to a suspected data exfiltration, which THREE pieces of volatile data should be collected first? (Choose three.)

Hard
13

A first responder is handling a compromised Linux server that is still powered on and actively communicating with an unknown external IP. The responder needs to collect volatile evidence while minimizing disruption. Which TWO actions should be performed to preserve the most volatile data in the correct order? (Choose two.)

Hard
14

During an incident response, a first responder needs to collect evidence from a Linux server that is still running. The server has sensitive data and cannot be shut down. Which technique is BEST for acquiring a forensic image of the hard disk?

Hard
15

You are a first responder for a medium-sized enterprise. The Help Desk received multiple reports that users cannot access the company's internal web application (app.example.com) hosted on a Windows Server 2019 VM. The server is also running a MySQL database and an FTP service for file transfers. You remote into the server and find that the web server (IIS) is still running, but the application pool is stopped. The event logs show multiple failed logon attempts from an external IP address (198.51.100.23) for the local administrator account around the time the issues started. The FTP service log shows successful anonymous logins from the same IP minutes before the web app failure. The MySQL log shows a query 'DROP TABLE users;' executed at 03:15 AM. The current time is 04:00 AM. What immediate action should you take?

Medium

Frequently asked questions

What does the Incident Response and First Responder Skills domain cover on the CHFI exam?
Be able to triage a live system: identify suspicious connections and processes, capture volatile data in the correct order, contain without destroying evidence, and document every action. The single most important thing is preserving volatile evidence before it is lost.
How many questions are in this domain?
This page lists all 15 Incident Response and First Responder Skills questions in the CHFI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Response and First Responder Skills questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ec-chfi EC-CHFI incident first response Practice Questions