Courseiva

GCIH · topic practice

Incident Response and Cyber Investigation practice questions

This GCIH domain covers the incident response lifecycle, forensic artifact collection, and adversary tradecraft analysis. Questions present scenarios requiring you to identify attacker techniques like living-off-the-land, select the right evidence sources, and apply preparation-phase controls. Expect exhibit-based items referencing process trees, Sysmon-style telemetry, and web server logs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Incident Response and Cyber Investigation

What the exam tests

What to know about Incident Response and Cyber Investigation

A candidate must map observed activity to attacker techniques, choose the correct forensic artifacts for a given scenario, and sequence incident response lifecycle phases. The most important thing is distinguishing legitimate administrative tool use from malicious LotL abuse when selecting evidence.

Identifying parent-child process relationships in Sysmon Event ID 1 and Windows process trees

Recognizing living-off-the-land binaries such as PowerShell, certutil, and wmic used by attackers

Selecting forensic artifacts including web server logs, memory captures, and network flow data

Applying preparation-phase controls like logging, baselining, and jump bag readiness

Watch out for

Common Incident Response and Cyber Investigation exam traps

  • ▸Assuming signature-based AV detects LotL activity; these tools are legitimate system binaries and often whitelisted
  • ▸Collecting only disk images and skipping volatile evidence like memory and active network connections
  • ▸Confusing preparation-phase tasks with detection or containment activities in the IR lifecycle

Practice set

Incident Response and Cyber Investigation questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Review the full subnetting walkthrough →

An organization experiences a ransomware attack. During the containment phase, the Incident Response team must decide between isolating the affected subnet or shutting down the critical database server. Which factor should be the primary driver for this decision?

Which THREE factors should an investigator consider when evaluating the integrity of digital evidence collected during an incident?

A GCIH incident handler is responding to a suspected data exfiltration incident on a Linux server. The handler needs to identify which processes are listening on network ports and which files they have open, to determine if a malicious backdoor is present. Which command should the handler use to list all open files and the processes that have them open?

A GCIH incident handler is investigating a compromised Windows 10 workstation. The attacker gained access using stolen credentials and then attempted to dump credentials from memory. The handler runs Sysinternals ProcDump with the -ma flag against lsass.exe to capture a full memory dump for analysis. The attempt fails with an 'Access Denied' error. Which of the following is the MOST likely reason for this failure?

Which TWO steps are critical during the 'Preparation' phase of the incident response lifecycle to ensure effective forensic investigation during a future security breach?

Refer to the exhibit. An analyst identifies these entries on a critical server. What should the analyst conclude regarding the process associated with PID 4?

Exhibit

C:\> netstat -ano | findstr :445
TCP 192.168.1.50:445 10.0.0.5:49152 ESTABLISHED 4
TCP 192.168.1.50:445 10.0.0.10:50221 ESTABLISHED 4

During a digital investigation, an incident responder is asked to preserve memory from a compromised Linux server. Which tool is most appropriate for a forensically sound memory acquisition?

An organization detects a web-based attack and wants to perform a thorough investigation. Which THREE artifacts should the team collect to analyze the adversary's entry point and activity?

Which phase of the incident response process is most likely to involve the creation of a 'lessons learned' report to improve future security posture?

Refer to the exhibit. An analyst deploys this policy to detect threats. Why is the 'parent_process' condition specifically targeting 'w3wp.exe'?

Exhibit

{
  "rule_name": "Suspicious_PowerShell_Execution",
  "conditions": {
    "command_line_contains": ["-enc", "-encodedcommand", "IEX"],
    "parent_process": "w3wp.exe"
  }
}

An incident responder discovers an attacker has established persistence using a Windows 'Run' key. What is the most important first step after identifying the malicious registry entry?

During an investigation, you observe an attacker using 'living-off-the-land' (LotL) techniques. Why is it difficult to detect this activity using traditional signature-based antivirus?

You are performing a live response and encounter a suspicious process. Which action should you take FIRST to gather the most intelligence without alerting the adversary or crashing the system?

Refer to the exhibit. Why might an investigator use the output of 'vssadmin' during a cyber investigation?

Exhibit

C:\> vssadmin list shadows
Contents of shadow copy set {a1b2c3d4...}
  - Shadow Copy ID: {e5f6g7h8...}
    Original Volume: (C:)
    Shadow Copy Volume: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1

An organization is responding to an Advanced Persistent Threat (APT). During the 'Eradication' phase, why is it critical to go beyond just removing identified malware?

A GCIH incident handler is investigating a suspected compromise on a Windows 10 workstation. The user reported unusual outbound network connections and sluggish performance. To determine the scope and impact of the incident, the handler must collect volatile evidence first. Which TWO artifacts should the handler prioritize to capture active network connections and running processes before memory is altered or lost? (Choose two.)

During a security incident, a GCIH analyst discovers that an attacker used PowerShell to download and execute a malicious script from a remote server. The analyst wants to determine the full command line and parent process of the PowerShell execution to understand the attack vector. Which Windows artifact should the analyst examine to retrieve this information?

An incident responder is reviewing an IDS alert and needs to determine whether a suspicious executable that ran on a Windows workstation has been seen in other attacks. Which framework should the responder consult to map the observed adversary behavior to known tactics, techniques, and procedures?

A SOC analyst receives a report that a workstation is beaconing to an unknown external IP every 60 seconds. The analyst runs netstat -anob and identifies the process responsible. The process is svchost.exe, but the parent process is not services.exe. Which of the following should the analyst do FIRST to determine if this is a malicious injection?

During an investigation of a compromised Linux web server, an incident responder needs to identify which user account was used to establish an outbound SSH session to an external IP address. Which artifact should the responder examine first?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Incident Response and Cyber Investigation sessions

Start a Incident Response and Cyber Investigation only practice session

Every question in these sessions is drawn from the Incident Response and Cyber Investigation domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Incident Response and Cyber Investigation?
A candidate must map observed activity to attacker techniques, choose the correct forensic artifacts for a given scenario, and sequence incident response lifecycle phases. The most important thing is distinguishing legitimate administrative tool use from malicious LotL abuse when selecting evidence.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Incident Response and Cyber Investigation questions in a focused session?
Yes — the session launcher on this page draws every question from the Incident Response and Cyber Investigation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.