Courseiva

GCIH Incident Response and Cyber Investigation Practice Question

Exhibit

C:\> vssadmin list shadows
Contents of shadow copy set {a1b2c3d4...}
  - Shadow Copy ID: {e5f6g7h8...}
    Original Volume: (C:)
    Shadow Copy Volume: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1

Refer to the exhibit. Why might an investigator use the output of 'vssadmin' during a cyber investigation?

⚠ Common exam trap

Students often think vssadmin is used exclusively for deleting backup files to prevent ransomware recovery, forgetting its critical forensic value for investigators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To recover previous versions of system files and registry hives for analysis.

Volume Shadow Copies are an essential artifact in Windows forensics. They allow an investigator to access older versions of files, including logs, registry hives, and malware binaries that the attacker might have modified or deleted to cover their tracks. By mounting these shadows, an investigator can perform 'time-travel' analysis, recovering evidence that is otherwise invisible on the live file system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To identify hidden partitions created by rootkits for persistence.

    Why it's wrong here

    vssadmin manages Volume Shadow Copies, which are snapshots of file system data. They do not show hidden partitions or disk structure modifications. While they can reveal files left behind in snapshots, they are not the correct tool for identifying malicious partition manipulation at the physical disk level.

  • ✓

    To recover previous versions of system files and registry hives for analysis.

    Why this is correct

    Shadow copies provide a point-in-time snapshot of the system. Investigators often use them to compare the current state of the system against a known-clean state or to recover deleted malicious files and modified configuration files that an attacker attempted to hide by overwriting them on the live disk.

  • ✗

    To check for unauthorized changes to the system's BIOS/UEFI firmware.

    Why it's wrong here

    Shadow copies store file system data from the OS volume. They do not have access to firmware, BIOS, or UEFI settings. Monitoring firmware integrity requires specialized hardware-level tools, and vssadmin is completely irrelevant for inspecting the low-level integrity of the system's boot hardware components.

  • ✗

    To list all currently active network sockets on the host.

    Why it's wrong here

    The vssadmin tool is strictly for managing Volume Shadow Copy Service (VSS) snapshots. It has no capabilities for querying network connections or socket activity. An investigator should use 'netstat' or 'Get-NetTCPConnection' to view network sockets, not this utility, which is limited to storage snapshots.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.