Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During an enterprise incident response, you are tasked with collecting volatile evidence from a compromised Windows workstation. Which two of the following are considered best practices for preserving volatile data? (Choose two.)

⚠ Common exam trap

The trap here is thinking that shutting down the system or disconnecting it from the network is a safe first step, but that destroys volatile evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run 'netstat -ano' to record active network connections and associated process IDs.

Capturing physical memory and recording active network connections are both essential for preserving volatile evidence. Memory contains running processes, encryption keys, and injected code, while netstat reveals current network activity that may indicate command-and-control or lateral movement. These steps should be performed before any action that alters the system state, such as shutdown or disconnection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately shut down the system to prevent further malicious activity and then create a forensic image of the hard drive.

    Why it's wrong here

    Shutting down the system destroys volatile evidence in memory, such as running processes and network connections. While creating a forensic image of the hard drive is important, it should not come at the expense of volatile data. The order should be: capture memory, then other volatile data, then consider shutting down for disk imaging if necessary. This option is a common mistake that leads to loss of critical evidence.

  • ✗

    Use a write blocker when connecting the hard drive to a forensic workstation to create a bit-for-bit image.

    Why it's wrong here

    Using a write blocker is a best practice for disk imaging, but it is not related to collecting volatile evidence. Volatile evidence resides in memory, network connections, and running processes, which are lost on shutdown. This option is about preserving non-volatile storage, which is important but not the focus of volatile evidence collection. It does not address the immediate need to capture data that will disappear.

  • ✓

    Run 'netstat -ano' to record active network connections and associated process IDs.

    Why this is correct

    Running netstat captures current network connections and listening ports, along with the process IDs. This is valuable for identifying command-and-control connections and lateral movement. It is a quick, non-intrusive command that should be run early in the collection process. The output can be correlated with process listings and memory analysis to understand the attacker's network activity. It is a best practice to document these connections before they change.

  • ✓

    Capture the contents of physical memory (RAM) using a forensic tool before shutting down the system.

    Why this is correct

    Capturing RAM is critical because it contains running processes, network connections, encryption keys, and other volatile data that will be lost on shutdown. Tools like WinPmem or Magnet RAM Capture can be used. This should be done before any other action that might alter memory, such as running antivirus scans. Preserving memory allows for deeper analysis of the attacker's activities and may reveal malware that is only in memory.

  • ✗

    Disconnect the workstation from the network before capturing any volatile data to prevent data leakage.

    Why it's wrong here

    Disconnecting from the network can cause loss of volatile network connections and may alert the attacker. It also prevents remote collection tools from working. In most cases, it is better to capture volatile data while the system is still connected, unless there is active data exfiltration that must be stopped immediately. Disconnecting should be a containment decision, not a default step before volatile data collection.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.