Courseiva

GCFA Enterprise Environment Incident Response Practice Question

Which THREE activities are considered best practices when preserving evidence from a cloud-based environment during an incident?

⚠ Common exam trap

Candidates often suggest deleting the instance to prevent further damage. This destroys volatile evidence; isolation and snapshotting are the correct non-destructive methods for cloud forensics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Take snapshots of all attached volumes for forensic imaging.

Evidence preservation in cloud environments requires non-destructive methods that maintain chain of custody while ensuring data integrity. By creating snapshots, isolating the affected instance, and extracting memory, responders ensure that the state of the system is preserved for deep forensic analysis. These steps are crucial because cloud instances are ephemeral and can be easily deleted or modified, which would destroy the evidence necessary to build a complete incident timeline and identify the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Take snapshots of all attached volumes for forensic imaging.

    Why this is correct

    Snapshots provide a point-in-time, read-only copy of the disk data. This is a forensically sound way to preserve evidence without affecting the live production system. It ensures that the state of the evidence remains static, allowing responders to conduct detailed analysis without the risk of contaminating the original data.

  • ✓

    Capture volatile memory using cloud-native imaging tools.

    Why this is correct

    Memory contains critical evidence of running processes, injected code, and open network connections that are lost upon reboot. Using cloud-native imaging tools to capture this memory before shutting down or isolating the instance is essential for performing a thorough investigation into sophisticated threats that do not leave disk traces.

  • ✗

    Shut down the instance immediately to stop the attack.

    Why it's wrong here

    Shutting down the instance wipes the volatile memory, destroying the most critical evidence of the attacker's activity. Forensically sound procedure dictates memory capture before any state-altering actions are taken. This approach ensures that all evidence is preserved for investigation, rather than being discarded during a hasty, poorly planned containment.

  • ✓

    Isolate the instance using security group rules.

    Why this is correct

    Isolating the instance prevents further communication with the attacker's command-and-control server while keeping the instance running for memory extraction. This is a critical step in preserving the state of the machine for forensic analysis while effectively containing the incident to prevent further damage to the surrounding infrastructure.

  • ✗

    Delete all ephemeral logs to save on cloud storage costs.

    Why it's wrong here

    Logs are vital evidence in any forensic investigation. Deleting them is a violation of basic incident response principles and destroys the timeline information needed to reconstruct the attacker's activities. Storage costs are a minor consideration compared to the legal and operational costs associated with an incomplete forensic investigation.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.