GCIH Network and Log Investigations Practice Question
An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?
⚠ Common exam trap
The trap here is assuming that DNS or route tracing tools can attribute network activity to a process, when only connection listing tools with PID output can do that.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
netstat -ano
Correlating a live network connection to its owning process is a core incident response task. The netstat -ano command provides the essential PID mapping, which can then be resolved to an executable using tasklist or Task Manager. This native capability allows rapid triage without installing additional tools, directly answering which process initiated the suspicious outbound transfer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
netstat -ano
Why this is correct
The -ano flags list all connections with their owning process ID (PID) in numeric form. Combined with Task Manager or tasklist, the PID maps directly to the executable, allowing the handler to identify which process initiated the suspicious outbound transfer. This is the fastest native method to correlate a live connection to its process without additional tooling.
- ✗
nslookup
Why it's wrong here
nslookup resolves DNS names to IP addresses or vice versa. While it could identify the hostname associated with the unfamiliar IP, it provides no information about which local process opened the connection. It cannot map a socket to a PID, so it fails to answer the core question of process attribution in this scenario.
- ✗
tracert
Why it's wrong here
tracert maps the network path to a destination by sending ICMP or UDP probes with increasing TTL values. It reveals intermediate routers but says nothing about local processes or active TCP connections. Using it here would waste time and not identify the originating process, making it irrelevant to the investigation.
- ✗
arp -a
Why it's wrong here
arp -a displays the current ARP cache, mapping IP addresses to MAC addresses on the local subnet. It is useful for detecting ARP spoofing or identifying local hosts, but it does not list TCP connections or associate them with processes. It cannot help correlate the outbound transfer to a specific executable.
Visual reference
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.