GCFA Introduction to Memory Forensics Practice Question
A responder has captured a memory image from a running Windows server and needs to preserve it for later analysis. Which action best maintains the forensic integrity of the acquired memory image?
⚠ Common exam trap
The trap here is equating any handling step with integrity preservation, when only cryptographic hashing provides a verifiable baseline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compute a cryptographic hash of the memory image immediately after acquisition and record it in the case notes.
Cryptographic hashing immediately after acquisition establishes a verifiable integrity baseline for the memory image. Storing the image on the source host, using proprietary compression before hashing, or inspecting it in a hex editor does not provide that assurance and may introduce risk. Hashing is the standard, defensible method to demonstrate the image has not been altered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compute a cryptographic hash of the memory image immediately after acquisition and record it in the case notes.
Why this is correct
Hashing the image right after acquisition creates a verifiable baseline for integrity. Any later comparison can confirm the image is unchanged. This is a fundamental forensic practice that supports admissibility and defensibility, and it applies directly to memory images just as it does to disk images, ensuring the evidence can be trusted throughout the investigation.
- ✗
Compress the memory image with a proprietary format to reduce its size before hashing.
Why it's wrong here
Compression can be acceptable if done carefully, but using a proprietary format before hashing introduces unnecessary risk and potential incompatibility. More importantly, the action described does not by itself ensure integrity; hashing should occur on the acquired image, and proprietary formats may hinder later analysis. This choice adds complexity without addressing the core integrity requirement.
- ✗
Open the memory image in a hex editor to verify its contents before storing it.
Why it's wrong here
Opening the image in a hex editor does not verify integrity and risks accidental modification. Verification is achieved through cryptographic hashing, not visual inspection. A hex editor may be useful during analysis, but using it immediately after acquisition does not preserve integrity and could compromise the evidence if any write occurs.
- ✗
Store the memory image on the same server from which it was captured to preserve chain of custody.
Why it's wrong here
Storing evidence on the source system is poor practice because the system may be compromised or later altered, risking contamination or loss. Chain of custody requires controlled storage on trusted media, not the original host. Keeping the image on the server undermines integrity and could allow an attacker to tamper with the evidence.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.