Courseiva

CHFI Incident Response and First Responder Skills Practice Question

During an incident response, a first responder needs to collect volatile data from a compromised Windows 10 system. The system has PowerShell v5.1 available. Which PowerShell cmdlet should be used to capture a list of currently running processes with their associated command lines?

⚠ Common exam trap

The trap here is assuming that Get-Process returns command-line arguments, when in fact it does not; command lines require querying the Win32_Process class via CIM or WMI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine

The Win32_Process CIM class includes the CommandLine property, which reveals the full command line for each process. Using Get-CimInstance with Select-Object for Name, ProcessId, and CommandLine provides a precise and efficient capture. Other options either lack command-line data or use deprecated cmdlets. This approach is reliable and non-intrusive for volatile data collection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Get-Process | Where-Object {$_.CommandLine -ne $null}

    Why it's wrong here

    Get-Process objects do not have a CommandLine property, so this filter would return nothing or error. This reflects a misunderstanding of PowerShell object properties. The correct property is available via CIM/WMI classes. This command would fail to capture the needed information.

  • ✓

    Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine

    Why this is correct

    Get-CimInstance Win32_Process retrieves process information including the CommandLine property, which shows the full command used to start each process. Selecting Name, ProcessId, and CommandLine provides a clear, concise list. This is essential for identifying malicious processes with suspicious arguments. It is a reliable method on Windows 10 with PowerShell v5.1.

  • ✗

    Get-WmiObject -Class Win32_Process | Export-Csv processes.csv

    Why it's wrong here

    Get-WmiObject is deprecated in favor of Get-CimInstance and may not be available or may perform slower. While it can retrieve Win32_Process, it does not automatically include CommandLine unless explicitly selected. Export-Csv would export all properties, but the command as written may still not capture command lines correctly. It is not the recommended approach on modern Windows.

  • ✗

    Get-Process | Format-List *

    Why it's wrong here

    Get-Process returns process objects but does not include command-line arguments by default. Format-List * displays all properties, but command line is not a standard property of Get-Process. This would miss critical details such as malicious script arguments. It is not the best choice for capturing command lines.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official EC-Council exam blueprint

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.