GCIH Incident Response and Cyber Investigation Practice Question
Exhibit
C:\> vssadmin list shadows
Contents of shadow copy set {a1b2c3d4...}
- Shadow Copy ID: {e5f6g7h8...}
Original Volume: (C:)
Shadow Copy Volume: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1Refer to the exhibit. Why might an investigator use the output of 'vssadmin' during a cyber investigation?
⚠ Common exam trap
Students often think vssadmin is used exclusively for deleting backup files to prevent ransomware recovery, forgetting its critical forensic value for investigators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To recover previous versions of system files and registry hives for analysis.
Volume Shadow Copies are an essential artifact in Windows forensics. They allow an investigator to access older versions of files, including logs, registry hives, and malware binaries that the attacker might have modified or deleted to cover their tracks. By mounting these shadows, an investigator can perform 'time-travel' analysis, recovering evidence that is otherwise invisible on the live file system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To identify hidden partitions created by rootkits for persistence.
Why it's wrong here
vssadmin manages Volume Shadow Copies, which are snapshots of file system data. They do not show hidden partitions or disk structure modifications. While they can reveal files left behind in snapshots, they are not the correct tool for identifying malicious partition manipulation at the physical disk level.
- ✓
To recover previous versions of system files and registry hives for analysis.
Why this is correct
Shadow copies provide a point-in-time snapshot of the system. Investigators often use them to compare the current state of the system against a known-clean state or to recover deleted malicious files and modified configuration files that an attacker attempted to hide by overwriting them on the live disk.
- ✗
To check for unauthorized changes to the system's BIOS/UEFI firmware.
Why it's wrong here
Shadow copies store file system data from the OS volume. They do not have access to firmware, BIOS, or UEFI settings. Monitoring firmware integrity requires specialized hardware-level tools, and vssadmin is completely irrelevant for inspecting the low-level integrity of the system's boot hardware components.
- ✗
To list all currently active network sockets on the host.
Why it's wrong here
The vssadmin tool is strictly for managing Volume Shadow Copy Service (VSS) snapshots. It has no capabilities for querying network connections or socket activity. An investigator should use 'netstat' or 'Get-NetTCPConnection' to view network sockets, not this utility, which is limited to storage snapshots.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.