GCFA Enterprise Environment Incident Response Practice Question
An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot be taken offline. Which method is most appropriate for acquiring the disk image while minimizing disruption?
⚠ Common exam trap
The trap here is assuming that any backup or shadow copy method is forensically sound, when only specialized live acquisition tools preserve the necessary integrity and completeness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a live acquisition tool like FTK Imager or Magnet ACQUIRE to create a forensic image of the disk while the system is running.
For a running server that cannot be taken offline, live acquisition with a tool like FTK Imager or Magnet ACQUIRE is the best option. These tools create a forensic image of the disk while the system is operational, preserving the data with minimal disruption. However, they should be used in conjunction with volatile data collection to capture memory and network state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a hardware write blocker and remove the disk to image it on a separate workstation.
Why it's wrong here
Removing the disk would require taking the server offline, which is not acceptable for a critical database. Hardware write blockers are ideal for dead-box forensics but are not suitable for live systems. This method would cause significant downtime and is not appropriate when the server must remain operational.
- ✓
Use a live acquisition tool like FTK Imager or Magnet ACQUIRE to create a forensic image of the disk while the system is running.
Why this is correct
Live acquisition tools such as FTK Imager or Magnet ACQUIRE can create a forensic image of the disk without taking the server offline. They capture the disk contents while the system is running, minimizing disruption. This is the most appropriate method for a critical server that cannot be shut down, though it may not capture volatile data, so that should be collected separately.
- ✗
Run the built-in Windows backup utility to create a system image to a network share.
Why it's wrong here
Windows backup creates a backup that may not be forensically sound, as it can exclude certain files and does not capture unallocated space. It also may not preserve metadata in a forensically acceptable manner. While it is non-disruptive, it is not suitable for forensic imaging because it lacks the integrity and completeness required for evidence.
- ✗
Use diskpart to create a shadow copy and then copy the volume to an external drive.
Why it's wrong here
Shadow copies are useful for accessing locked files but are not a forensic imaging method. Copying files from a shadow copy does not capture the entire disk, including unallocated space and file system metadata. This approach would result in an incomplete and potentially altered image, making it unsuitable for forensic analysis.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.