Courseiva

GCIH Incident Response and Cyber Investigation Practice Question

A GCIH incident handler is investigating a suspected compromise on a Windows 10 workstation. The user reported unusual outbound network connections and sluggish performance. To determine the scope and impact of the incident, the handler must collect volatile evidence first. Which TWO artifacts should the handler prioritize to capture active network connections and running processes before memory is altered or lost? (Choose two.)

⚠ Common exam trap

Many candidates confuse non-volatile artifacts like event logs or scheduled tasks with volatile data that must be captured immediately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Output of the `netstat -anob` command

In incident response, volatile data such as active network connections and running processes must be collected first because they are lost when the system is shut down or memory is altered. The `netstat -anob` command provides a snapshot of network connections and associated processes, while `tasklist /v` lists running processes with details. Together, they offer a current view of system activity, enabling the handler to identify malicious processes and their network communications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    List of scheduled tasks from the Task Scheduler library

    Why it's wrong here

    Scheduled tasks are stored in the registry and file system, making them non-volatile. They are useful for identifying persistence mechanisms, but they do not reveal active network connections or running processes. In the scenario, the handler needs to capture volatile evidence first; scheduled tasks can be collected later without loss of data.

  • ✗

    Contents of the Windows Security event log

    Why it's wrong here

    The Windows Security event log is stored on disk and is not considered volatile. While it contains valuable information such as logon events and process creation (if auditing is enabled), it does not provide a real-time view of active network connections or currently running processes. Collecting it is important but not a priority for capturing volatile network state.

  • ✗

    Contents of the `C:\Windows\Prefetch` directory

    Why it's wrong here

    Prefetch files are stored on disk and contain metadata about executed programs, but they are not volatile in the same sense as active network connections or running processes. They can provide historical evidence of execution, but they do not show what is currently running or connected. Therefore, they are not a priority for immediate volatile data collection.

  • ✓

    Output of the `netstat -anob` command

    Why this is correct

    The `netstat -anob` command displays all active network connections, listening ports, and the associated executable names (with the -b switch) and process IDs (with the -o switch). This provides an immediate snapshot of which processes are communicating over the network, directly addressing the need to capture active connections and running processes. It is a core volatile data collection step in incident response.

  • ✓

    Output of the `tasklist /v` command

    Why this is correct

    The `tasklist /v` command lists all currently running processes along with detailed information such as the user account, CPU time, and window title. This captures the active process list, which is volatile and essential for understanding what is executing on the system. It complements network connection data by showing the processes behind the connections.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.