Courseiva

GCFA · topic practice

Enterprise Environment Incident Response practice questions

This GCFA domain covers incident response across enterprise networks and cloud services: triaging compromised Windows and Linux hosts, preserving volatile and non-volatile evidence, containing active threats without destroying data, and reconstructing adversary activity from logs and artifacts. Questions present realistic scenarios and ask you to choose the correct acquisition, containment, or analysis action.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Enterprise Environment Incident Response

What the exam tests

What to know about Enterprise Environment Incident Response

Be able to select the right acquisition and containment method for a live enterprise system, then pivot across Windows, Linux, and cloud artifacts to reconstruct the intrusion. The single most important thing: preserve volatile evidence before shutting anything down.

Live memory acquisition on running Windows servers using tools like WinPmem or FTK Imager

Analyzing Linux authentication logs such as /var/log/auth.log and journalctl for SSH brute-force and successful logins

Identifying cloud email compromise artifacts including mailbox forwarding rules and audit logs

Containment decisions that stop ransomware spread while preserving forensic evidence on file servers

Watch out for

Common Enterprise Environment Incident Response exam traps

  • ▸Assuming a full disk image is always required; volatile memory and live system state may be lost if the host is powered off first.
  • ▸Overlooking cloud-side evidence like mailbox forwarding rules or audit logs because focus stays on endpoint artifacts.
  • ▸Containing too aggressively by wiping or rebuilding systems, destroying evidence needed to determine scope and root cause.

Practice set

Enterprise Environment Incident Response questions

20 questions · select your answer, then reveal the explanation

An incident responder identifies a suspicious PowerShell process executing encoded commands on an enterprise server. To effectively contain the host while preserving volatile evidence for forensic analysis, which action should the responder prioritize?

Refer to the exhibit. An analyst observes this process entry on a server that has triggered a high-severity alert. Based on the provided metadata, why is this process considered highly suspicious?

Exhibit

{"process_name": "svchost.exe", "pid": 4920, "parent_pid": 872, "user": "SYSTEM", "command_line": "C:\\Windows\\System32\\svchost.exe -k netsvcs -p", "network_connections": [{"proto": "tcp", "local_ip": "10.0.0.5", "remote_ip": "192.168.1.50", "remote_port": 443}]}

When conducting an enterprise incident response, why is it essential to establish a dedicated Out-of-Band (OOB) communication channel?

Refer to the exhibit. An analyst is investigating a suspected breach. Given the log entries, which immediate hypothesis is most supported by the evidence?

Exhibit

log_entry: {"timestamp": "2023-10-12T14:22:01Z", "event": "ServiceInstallation", "service_name": "BackdoorSvc", "bin_path": "C:\\Windows\\Temp\\svchost.exe", "user": "Admin1"}
log_entry: {"timestamp": "2023-10-12T14:25:10Z", "event": "ProcessCreation", "process": "powershell.exe", "command": "-enc YQBkAGQALQBhAGQAZwByAG8AdQBwAG0AZQBtAGJlAHIA..."}

An incident responder identifies an active PowerShell script executing encoded commands in memory. Which memory forensics technique is most effective for extracting the deobfuscated script content during the live response phase?

An incident responder discovers an attacker using Domain Fronting to bypass network egress filtering. What is the most effective way to mitigate this technique at the perimeter?

Which THREE of the following represent common artifacts of lateral movement found during a Windows investigation?

Which phase of the incident response lifecycle focuses on identifying the root cause and determining if the incident is ongoing?

During an enterprise-wide incident, you are tasked with collecting volatile evidence from hundreds of compromised Windows 10 endpoints. Which approach best preserves the integrity and order of volatile data while enabling centralized analysis?

An enterprise incident response team is investigating a breach involving a compromised domain controller. The attacker used Kerberos ticket manipulation to maintain persistence. Which TWO of the following forensic artifacts should be prioritized for collection to identify the compromised accounts and the persistence mechanism? (Choose two.)

An incident responder is analyzing a memory dump from a Windows 10 host compromised by a sophisticated adversary. The adversary used process hollowing to inject malicious code into a legitimate process. Which Volatility 3 plugin is most appropriate to detect the hollowed process by comparing the in-memory image of the executable with its on-disk counterpart?

During an enterprise incident response engagement, a responder is collecting volatile data from a compromised Windows Server 2019 system before initiating a full disk image. The responder needs to capture the current list of network connections, associated process IDs, and the executable paths responsible for each connection. Which single Windows-native command should the responder run to reliably obtain this information on the live system?

During an incident, you need to acquire volatile memory from a running Windows 10 workstation suspected of malware infection. The system is in a locked state, and you cannot log in interactively. Which method is most appropriate to capture memory while minimizing alteration of the system state?

A security analyst is reviewing network traffic logs and notices a large volume of outbound traffic from an internal server to an unknown external IP address on port 443. The traffic occurs regularly every 60 seconds and the payload size is consistent. The analyst suspects command-and-control (C2) communication. Which of the following techniques is the adversary MOST likely using to evade detection?

During an enterprise incident response, you discover that an attacker used a scheduled task to maintain persistence on a Windows Server 2019 host. The task is configured to run a malicious script every hour. Which artifact should you examine to determine the exact command line and the user account under which the task runs?

An enterprise incident response team is preparing to acquire volatile evidence from a compromised Windows server. The server is running critical business applications, and management wants to minimize downtime. Which TWO of the following actions should the team perform to properly capture volatile data while preserving system integrity? (Choose two.)

An incident responder is analyzing a memory dump from a compromised Windows 10 workstation. The attacker used a fileless malware technique that injected malicious code into a legitimate process. The responder needs to identify the injected code and the process it is running in. Which of the following memory forensics techniques is MOST appropriate for this task?

During a post-incident review, a team realizes they missed a critical indicator of compromise (IOC) because they did not normalize their log data. What is the primary benefit of log normalization in an enterprise incident response environment?

Which phase of the incident response lifecycle is most directly responsible for ensuring that an enterprise environment is returned to a secure, verified state after an intrusion?

An organization detects a sophisticated adversary attempting to move laterally using Pass-the-Hash (PtH) techniques. Which THREE of the following configurations or practices are most effective at mitigating this risk?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enterprise Environment Incident Response sessions

Start a Enterprise Environment Incident Response only practice session

Every question in these sessions is drawn from the Enterprise Environment Incident Response domain — nothing else.

Related practice questions

Related GCFA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCFA exam test about Enterprise Environment Incident Response?
Be able to select the right acquisition and containment method for a live enterprise system, then pivot across Windows, Linux, and cloud artifacts to reconstruct the intrusion. The single most important thing: preserve volatile evidence before shutting anything down.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enterprise Environment Incident Response questions in a focused session?
Yes — the session launcher on this page draws every question from the Enterprise Environment Incident Response domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCFA topics?
Use the topic links above to move to related areas, or go back to the GCFA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCFA exam covers. They are not copied from any real exam or dump site.