Courseiva

GCIH Incident Response and Cyber Investigation Practice Question

An incident responder is preparing to acquire a forensic image of a compromised Windows server. The server is still running, and the responder needs to capture volatile data first. Which of the following should be collected FIRST according to the order of volatility?

⚠ Common exam trap

The trap here is focusing on disk-based artifacts like event logs or temporary files because they are familiar, while overlooking that RAM is the most volatile and must be captured first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contents of physical memory (RAM).

According to the order of volatility, physical memory is the most volatile and should be captured first. It contains running processes, network connections, and potentially malicious code that exists only in RAM. Temporary files, network configuration, and event logs are less volatile and can be collected afterward. Capturing memory first ensures that critical evidence is preserved before it is lost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network configuration and ARP cache.

    Why it's wrong here

    Network configuration and ARP cache are volatile but less so than RAM. They can be captured after memory. While important for understanding network connections, they are not as time-sensitive as memory contents, which change constantly and are lost on power-off.

  • ✗

    Windows Event Logs.

    Why it's wrong here

    Event logs are stored on disk and are less volatile than memory. They persist across reboots, although they can be overwritten. They should be collected after memory and other volatile data. Prioritizing logs over RAM would miss critical in-memory evidence like injected code or encryption keys.

  • ✗

    Temporary files on the system drive.

    Why it's wrong here

    Temporary files are less volatile than memory; they persist until deleted or overwritten. They may contain useful artifacts, but they are not the first priority. Collecting them before memory could waste time and allow memory-resident evidence to be lost if the system reboots or crashes.

  • ✓

    Contents of physical memory (RAM).

    Why this is correct

    Physical memory is the most volatile and contains running processes, network connections, and encryption keys. It is lost when the system is powered off. According to the order of volatility, RAM should be captured before any disk or less volatile data to preserve critical evidence that may not exist elsewhere.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.