GCIH Incident Response and Cyber Investigation Practice Question
During a digital investigation, an incident responder is asked to preserve memory from a compromised Linux server. Which tool is most appropriate for a forensically sound memory acquisition?
⚠ Common exam trap
Candidates often suggest using standard system tools like 'dd' or 'cat' on /dev/mem, which are not forensically sound and can corrupt the memory state or produce inconsistent results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
LiME (Linux Memory Extractor) to generate an image file for offline analysis.
Forensic acquisition requires tools that do not alter the target system's state or metadata significantly. In Linux, LiME (Linux Memory Extractor) is the standard for generating a memory image while minimizing interference. Understanding tool limitations is critical, as improper collection can destroy volatile data, overwrite evidence, or lead to kernel panics, which would invalidate the integrity of the collected memory dump for subsequent analysis and courtroom admissibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'dd' command to copy /dev/mem directly to a remote storage server.
Why it's wrong here
Using 'dd' on /dev/mem is unreliable on modern Linux kernels due to memory protection features and access restrictions. It often results in incomplete dumps or system crashes, making it an inferior choice compared to specialized tools designed to interact safely with the kernel to extract volatile memory contents.
- ✓
LiME (Linux Memory Extractor) to generate an image file for offline analysis.
Why this is correct
LiME is the industry-standard tool for Linux memory acquisition because it is specifically designed to handle the complexities of kernel memory. It minimizes system impact and can be used to stream the memory image over the network, ensuring that the evidence is captured with high fidelity and integrity.
- ✗
The 'cat' command to pipe the contents of /proc/kcore into a file.
Why it's wrong here
While /proc/kcore provides a view of system memory, it is not a forensically sound method for acquisition. The operating system may modify the representation of this file in real-time, and it does not capture the full state of physical memory required for a comprehensive forensic analysis of the system.
- ✗
Installing a commercial agent to automate the imaging process via a GUI.
Why it's wrong here
Installing new software during an investigation is discouraged as it alters the system state, potentially overwriting evidence. Incident responders should prefer tools that can be run from a trusted, external source or loaded via a module without leaving a significant footprint on the disk or modifying critical configuration files.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.