CHFI Incident Response and First Responder Skills Practice Question
During an incident response, a first responder needs to collect volatile data from a compromised Windows 10 system. The system has PowerShell v5.1 available. Which PowerShell cmdlet should be used to capture a list of currently running processes with their associated command lines?
⚠ Common exam trap
The trap here is assuming that Get-Process returns command-line arguments, when in fact it does not; command lines require querying the Win32_Process class via CIM or WMI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine
The Win32_Process CIM class includes the CommandLine property, which reveals the full command line for each process. Using Get-CimInstance with Select-Object for Name, ProcessId, and CommandLine provides a precise and efficient capture. Other options either lack command-line data or use deprecated cmdlets. This approach is reliable and non-intrusive for volatile data collection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Get-Process | Where-Object {$_.CommandLine -ne $null}
Why it's wrong here
Get-Process objects do not have a CommandLine property, so this filter would return nothing or error. This reflects a misunderstanding of PowerShell object properties. The correct property is available via CIM/WMI classes. This command would fail to capture the needed information.
- ✓
Get-CimInstance Win32_Process | Select-Object Name, ProcessId, CommandLine
Why this is correct
Get-CimInstance Win32_Process retrieves process information including the CommandLine property, which shows the full command used to start each process. Selecting Name, ProcessId, and CommandLine provides a clear, concise list. This is essential for identifying malicious processes with suspicious arguments. It is a reliable method on Windows 10 with PowerShell v5.1.
- ✗
Get-WmiObject -Class Win32_Process | Export-Csv processes.csv
Why it's wrong here
Get-WmiObject is deprecated in favor of Get-CimInstance and may not be available or may perform slower. While it can retrieve Win32_Process, it does not automatically include CommandLine unless explicitly selected. Export-Csv would export all properties, but the command as written may still not capture command lines correctly. It is not the recommended approach on modern Windows.
- ✗
Get-Process | Format-List *
Why it's wrong here
Get-Process returns process objects but does not include command-line arguments by default. Format-List * displays all properties, but command line is not a standard property of Get-Process. This would miss critical details such as malicious script arguments. It is not the best choice for capturing command lines.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.