Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An organization is deploying an EDR solution to improve incident response capabilities. What is the most critical factor to consider when configuring EDR policies for a production environment?

⚠ Common exam trap

Candidates frequently choose aggressive blocking postures, underestimating the business disruption caused by false positives when deploying security controls in sensitive production environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Balancing security posture with the risk of operational impact.

EDR policies must be carefully tuned to prevent false positives that can lead to system instability, such as inadvertently blocking critical business processes or causing performance degradation. In production, an 'alert-only' mode is often implemented first to gather data and validate the impact. Without proper testing and tuning, a overly aggressive EDR configuration can disrupt legitimate operations, causing more damage to business productivity than the threats the EDR is intended to mitigate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring the EDR agent is configured to delete all suspicious files automatically.

    Why it's wrong here

    Automatic deletion of files in a production environment is extremely dangerous. It can lead to the deletion of critical system files if a false positive occurs, causing system crashes or service outages. Best practice is to isolate or quarantine the file, not delete it, allowing for manual verification and restoration.

  • ✓

    Balancing security posture with the risk of operational impact.

    Why this is correct

    Production environments require high availability. An EDR policy that is too aggressive might block legitimate processes, leading to critical service downtime. Balancing security with operational stability through testing and monitoring is the most important factor to ensure the EDR adds value without negatively impacting core business productivity.

  • ✗

    Forcing all EDR logs to be stored in the cloud for infinite retention.

    Why it's wrong here

    While log retention is important, it is not the most critical configuration factor for a production environment. Storage location and duration are secondary to the operational stability of the agents themselves. The primary risk is the agent's impact on system performance and the potential for service disruption due to policy enforcement.

  • ✗

    Disabling all other security tools to prevent agent conflict.

    Why it's wrong here

    EDR is a layer within a defense-in-depth strategy, not a replacement for other controls. Disabling existing firewalls, antivirus, or other security tools creates significant visibility gaps and leaves the organization vulnerable. Conflicts between security agents should be resolved through vendor-recommended exclusion lists, not by removing existing, necessary security layers.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.