GCIH Incident Response and Cyber Investigation Practice Question
An incident responder discovers an attacker has established persistence using a Windows 'Run' key. What is the most important first step after identifying the malicious registry entry?
⚠ Common exam trap
Candidates often immediately delete the registry key to stop the persistence. This destroys forensic evidence, preventing the responder from understanding the attacker's origin and full extent of the compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the registry state and the associated binary file for analysis.
Identifying the persistence mechanism is only the first step. Before removal, the responder must ensure that evidence is captured, as registry keys can provide valuable data about the attacker's tools and techniques. After imaging the state, the responder must safely remove the entry and then investigate how the attacker initially gained the access required to modify the registry in the first place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately delete the registry key to stop the persistence mechanism.
Why it's wrong here
Deleting the key immediately destroys the forensic context, such as the path to the malicious executable, which is critical for understanding the attack's scope. Proper response requires preserving the state of the system first to allow for a full investigation before remediating the specific persistence point identified.
- ✓
Capture the registry state and the associated binary file for analysis.
Why this is correct
Capturing the state and the binary allows for thorough forensic analysis, such as identifying the malware's capabilities and its command-and-control infrastructure. This information is vital for scoping the incident, checking for other infected systems, and ensuring that the removal process is successful and leaves no residual malicious components behind.
- ✗
Reimage the affected workstation to ensure total eradication of the malware.
Why it's wrong here
Reimaging is a valid remediation step, but it should only happen after analysis and containment have been performed. Jumping straight to reimaging skips the critical identification of the root cause and the intelligence gathering required to detect if other systems in the environment have been compromised by similar means.
- ✗
Change all user and service account passwords on the local system.
Why it's wrong here
While credential rotation is part of the recovery process, it is not the first step when a persistence mechanism is found. The responder must first understand how the persistence was placed to prevent the attacker from simply resetting the persistence mechanism or using other credentials to regain access after password changes.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.