GCFA Enterprise Environment Incident Response Practice Question
During an enterprise incident response involving a compromised Windows server, you need to acquire volatile evidence in a forensically sound manner. Which TWO of the following actions should be performed first to preserve the most volatile data? (Choose two.)
⚠ Common exam trap
The trap here is assuming that disk imaging or event log export should be done first because they are commonly emphasized, but they are less volatile than RAM and network state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of physical memory (RAM) using a tool like WinPmem or DumpIt.
The order of volatility dictates that physical memory and active network connections are the most perishable. Capturing RAM preserves running processes and encryption keys, while recording network connections captures transient command-and-control activity. These two actions must be performed first to prevent loss of critical evidence before moving to less volatile sources like disk images or event logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Capture the contents of physical memory (RAM) using a tool like WinPmem or DumpIt.
Why this is correct
Physical memory is the most volatile evidence and contains running processes, network connections, and encryption keys. Capturing it first preserves data that would be lost on shutdown or reboot. Tools like WinPmem or DumpIt create a forensic image of RAM that can later be analyzed for artifacts not found on disk, making this a critical first step in volatile evidence collection.
- ✗
Export the Windows Event Logs to a secure location.
Why it's wrong here
Windows Event Logs are stored on disk and are less volatile than memory or network connections. While they should be collected, they are not the most volatile evidence. Exporting them can be done after capturing RAM and network state, as they are not immediately lost on shutdown. Focusing on logs first would delay the capture of more perishable data.
- ✗
Take screenshots of the desktop and open applications.
Why it's wrong here
Screenshots can provide context but are not a priority for volatile evidence collection. They capture visual information that may be useful for documentation, but they do not preserve critical forensic artifacts like memory-resident malware or network connections. This action should be performed after the most volatile data has been secured.
- ✗
Create a forensic image of the system drive using FTK Imager or dd.
Why it's wrong here
Creating a forensic image of the system drive is important but less volatile than memory or network state. Disk contents persist across reboots and can be acquired later without significant loss. Prioritizing disk imaging over memory and network connections would risk losing critical volatile evidence that cannot be recovered from the disk image alone.
- ✓
Record active network connections and listening ports using netstat -anob.
Why this is correct
Active network connections and listening ports are highly volatile and can change rapidly. Using netstat -anob captures the current state, including the owning process, which is essential for identifying command-and-control channels or lateral movement. This data is lost once connections close, so it must be collected early in the response to preserve a snapshot of network activity.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.