GCFA Enterprise Environment Incident Response Practice Question
An organization is deploying an EDR solution across a hybrid environment. Which TWO of the following tasks are critical for ensuring effective incident response visibility?
⚠ Common exam trap
Candidates focus exclusively on threat intelligence feeds or endpoint isolation tools, ignoring the foundational requirement for comprehensive telemetry collection and tested playbooks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configuring full-stack telemetry collection across all managed endpoints.
Successful EDR deployment requires both technical configuration and operational integration. Ensuring comprehensive coverage across all endpoints prevents blind spots where attackers can hide, while defining automated response playbooks allows the IR team to scale their efforts during high-velocity incidents. These tasks are foundational to reducing mean time to respond, as they ensure high-fidelity telemetry is available and actionable, allowing for rapid containment of threats before they escalate across the enterprise network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Excluding all antivirus-flagged files from the EDR scanning scope.
Why it's wrong here
Excluding files based on antivirus flags is dangerous and creates massive security gaps. Attackers frequently use legitimate tools or mimic antivirus signatures to bypass controls. An incident response strategy must be inclusive, monitoring all activity to ensure malicious behavior is detected even when masked by common file or process names.
- ✓
Configuring full-stack telemetry collection across all managed endpoints.
Why this is correct
Full-stack telemetry—including process creation, network connections, registry changes, and file system modifications—is essential for reconstructing an attacker's timeline. Without this data, responders lack the context needed to identify lateral movement or command-and-control communication, rendering the EDR tool ineffective at providing a comprehensive picture of the incident's scope.
- ✓
Defining and testing automated containment playbooks for high-severity alerts.
Why this is correct
Automated playbooks ensure that initial containment steps, such as host isolation or account suspension, occur immediately upon detection. This reduces the attacker's dwell time significantly. Testing these playbooks is equally vital to ensure they do not cause unintended operational disruptions while protecting the environment from ongoing malicious activity during an incident.
- ✗
Disabling kernel-mode auditing to improve endpoint performance metrics.
Why it's wrong here
Kernel-mode auditing is vital for detecting rootkits and advanced persistent threats that operate at the lowest levels of the OS. Disabling it to save CPU cycles sacrifices critical visibility for a minor performance gain. Security tools must prioritize visibility into low-level execution to detect sophisticated techniques that user-mode monitoring misses.
- ✗
Restricting data retention to 24 hours to comply with privacy regulations.
Why it's wrong here
A 24-hour retention period is insufficient for most forensic investigations, as attackers often remain undetected for weeks or months. Incident responders need historical telemetry to perform root cause analysis and scope an incident. Privacy regulations generally allow for data retention if it is strictly tied to legitimate security monitoring purposes.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.