GCFA Enterprise Environment Incident Response Practice Question
During an enterprise incident, your team identifies that an attacker has deployed a ransomware variant that encrypts files on a critical file server. The attacker also exfiltrated sensitive data before encryption. Which of the following best describes the appropriate containment strategy?
⚠ Common exam trap
The trap here is assuming that shutting down the server is the best way to stop encryption, but that destroys volatile evidence and may hinder recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately disconnect the file server from the network, preserve volatile memory, and then proceed with eradication and recovery after scoping the full extent of the compromise.
The correct approach is to contain the incident by disconnecting the server to stop further encryption and potential lateral movement, while preserving volatile memory for forensic analysis. It is essential to scope the full extent of the compromise before eradication and recovery, as the attacker may have other footholds. This balanced approach aligns with incident response best practices for ransomware with data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate the file server from the network by disabling its network interface and then restore from the most recent backup.
Why it's wrong here
Isolating the server is a containment step, but immediately restoring from backup without preserving volatile evidence and understanding the attacker's persistence could allow re-infection. The attacker may have established backdoors elsewhere, and restoring may destroy forensic artifacts. Containment should also consider the exfiltration, which may require network-level blocking and coordination with legal/PR teams. This option oversimplifies the response.
- ✗
Shut down the file server immediately to stop the encryption process and prevent the attacker from accessing any further data.
Why it's wrong here
Shutting down the server may stop encryption but also destroys volatile evidence in memory, such as encryption keys, running processes, and network connections. This hinders forensic analysis and may prevent recovery of encrypted files if keys are in memory. Proper containment involves isolating the system while preserving evidence, not simply powering it off.
- ✓
Immediately disconnect the file server from the network, preserve volatile memory, and then proceed with eradication and recovery after scoping the full extent of the compromise.
Why this is correct
This approach correctly prioritizes containment (disconnecting the server) to stop further encryption and potential lateral movement, while also preserving volatile evidence (memory) for forensic analysis. It acknowledges the need to scope the incident before eradication and recovery, which is critical because the attacker may have compromised other systems or established persistence. This aligns with best practices for handling a ransomware incident with data exfiltration.
- ✗
Leave the server online to monitor the attacker's activity and gather more intelligence, while blocking outbound traffic to known command-and-control servers.
Why it's wrong here
Leaving the server online risks further encryption and potential spread to other systems. While monitoring can provide intelligence, in a ransomware scenario the priority is to stop the damage. Blocking outbound C2 traffic may not stop encryption if the ransomware is already deployed and operating offline or via other channels. This option is too risky and may lead to additional data loss.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.