Courseiva

GCIH Incident Response and Cyber Investigation Practice Question

A SOC analyst receives a report that a workstation is beaconing to an unknown external IP every 60 seconds. The analyst runs netstat -anob and identifies the process responsible. The process is svchost.exe, but the parent process is not services.exe. Which of the following should the analyst do FIRST to determine if this is a malicious injection?

⚠ Common exam trap

The trap here is assuming that any svchost.exe with an unusual parent is automatically malicious and should be terminated immediately, without gathering volatile evidence first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture a memory dump of the svchost.exe process and examine its loaded modules.

The correct first step is to capture a memory dump of the suspicious svchost.exe process. This preserves volatile evidence like injected code and network connections, allowing the analyst to confirm malicious activity before taking disruptive actions. Terminating the process or running an AV scan may destroy evidence or miss fileless malware, while event logs alone may not show the injection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terminate the svchost.exe process immediately to stop the beaconing.

    Why it's wrong here

    Terminating svchost.exe could cause system instability or a blue screen, and it destroys volatile evidence needed to understand the injection. The goal is to investigate the anomalous parent-child relationship, not to disrupt it before collecting memory and process details. Immediate termination also tips off the attacker, potentially triggering destructive actions.

  • ✗

    Run a full antivirus scan on the workstation to detect and remove the malware.

    Why it's wrong here

    A full antivirus scan may take hours and could miss fileless injection, as the malicious code resides only in memory. It also might delete artifacts before they are collected. The immediate priority is to determine if the anomaly is malicious by examining the process, not to remediate blindly.

  • ✓

    Capture a memory dump of the svchost.exe process and examine its loaded modules.

    Why this is correct

    A memory dump preserves the injected code, strings, and network artifacts, allowing the analyst to confirm process hollowing or injection. Examining loaded modules can reveal unsigned or suspicious DLLs. This is the least disruptive first step that gathers crucial evidence before any containment action.

  • ✗

    Check the Windows Event Log for service creation events around the same time.

    Why it's wrong here

    While event logs are valuable, service creation events may not capture the injection into an existing svchost.exe process. The anomalous parent indicates the process was likely started by something other than services.exe, so memory analysis is more direct. Logs alone may not reveal the injected code or its capabilities.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.