GCFA Enterprise Environment Incident Response Practice Question
Which of the following describes the 'Principle of Least Privilege' applied to incident response accounts?
⚠ Common exam trap
Candidates often interpret 'Least Privilege' as 'using a regular user account'. In an IR context, it means providing the absolute minimum access required for the specific forensic task, not just 'low' access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Limiting IR account access to only the specific data and systems needed for the investigation.
Using dedicated, limited-scope accounts for incident response ensures that if the responder's account is compromised, the attacker does not gain enterprise-wide administrative access. By providing only the permissions necessary for the investigation—such as read-only access to logs or forensic imaging permissions—the risk of accidental or malicious damage to the production environment is minimized, ensuring that the integrity of the IR process remains intact even in a hostile or complex environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a Domain Admin account for all investigation tasks to avoid access issues.
Why it's wrong here
Using a Domain Admin account for IR tasks is a high-risk practice. If that account's credentials are harvested by an attacker or if the responder accidentally executes a destructive command, the entire domain is compromised. IR should use granularly assigned permissions that match the specific task requirements, not broad administrative access.
- ✗
Granting forensic responders full system access to all network segments.
Why it's wrong here
Granting blanket access to the entire network violates the Principle of Least Privilege. Responders should only have access to the specific segments and systems currently under investigation. Broad network access creates unnecessary risk and increases the impact if the responder's credentials or workstation are compromised during an active incident.
- ✓
Limiting IR account access to only the specific data and systems needed for the investigation.
Why this is correct
By limiting the permissions of an IR account to exactly what is needed—such as log reading or forensic disk access—the organization mitigates the risk of credential theft. This practice ensures that even if an account is compromised, the attacker is limited in their ability to escalate or expand their foothold.
- ✗
Ensuring all IR accounts have a shared password for rapid response coordination.
Why it's wrong here
Shared credentials for IR accounts are a major security failure. They destroy accountability and auditability, making it impossible to determine which specific responder performed which action. Furthermore, if one person's password is stolen, the entire incident response capability is immediately compromised, creating a massive security vulnerability for the entire enterprise.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.