GCFA Enterprise Environment Incident Response Practice Question
An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)
⚠ Common exam trap
The trap here is equating containment with immediate shutdown or reimaging, when those actions destroy the volatile evidence that ransomware investigations depend on.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate affected servers from the network at the switch or EDR level while keeping them powered on
Isolating affected servers at the network layer stops the spread without destroying volatile evidence, and capturing memory before containment preserves fragile artifacts such as encryption keys and active processes. Together they satisfy containment and preservation. Powering off, reimaging, or deleting files would destroy evidence or recovery options and do not represent a balanced response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage all affected servers immediately to restore business operations
Why it's wrong here
Reimaging destroys all forensic evidence on the affected systems, including file system artifacts, logs, and malware remnants. It may restore operations quickly, but it eliminates the ability to determine root cause, scope, and whether the adversary retains persistence elsewhere. This action is premature before evidence is collected and analyzed.
- ✓
Isolate affected servers from the network at the switch or EDR level while keeping them powered on
Why this is correct
Network isolation via switch ACLs or EDR containment stops lateral spread and command-and-control communication while preserving volatile memory, running processes, and active sessions for forensic capture. It maintains system state for memory acquisition and allows the team to collect live evidence before any shutdown, satisfying both containment and preservation goals.
- ✗
Immediately power off all affected servers to halt encryption activity
Why it's wrong here
Powering off servers destroys volatile memory contents such as running processes, network connections, and encryption keys that may be critical for forensics and decryption. It also may leave file system transactions in an inconsistent state. While it stops encryption, it sacrifices volatile evidence and complicates recovery, so it is not a balanced choice.
- ✓
Capture a memory image of each affected server before any containment action
Why this is correct
Acquiring volatile memory first preserves running processes, encryption keys, and network artifacts that would be lost on shutdown or reboot. In a ransomware incident, memory may contain the encryption key or the malware's configuration. Capturing memory before containment ensures the most fragile evidence is secured while the system is still in its compromised state.
- ✗
Delete all encrypted files to prevent the ransomware from spreading further
Why it's wrong here
Deleting encrypted files does not stop ransomware propagation and destroys potential evidence and recovery options. Encrypted files may be needed for ransom negotiation, decryption tool validation, or forensic analysis of the encryption routine. This action is destructive and counterproductive to both containment and investigation.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.