GCIH Incident Response and Cyber Investigation Practice Question
You are performing a live response and encounter a suspicious process. Which action should you take FIRST to gather the most intelligence without alerting the adversary or crashing the system?
⚠ Common exam trap
Candidates often jump to disk imaging or memory dumps. They fail to prioritize volatile data like network connections and process lists, which are easily lost and provide immediate, low-impact context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture volatile data, including process listings, open handles, and network connections.
In live response, the principle of 'least intrusive first' is paramount. Collecting volatile data (like process lists and network connections) should always precede disk-based forensic imaging. By capturing the state of the system first, you ensure that you obtain the memory-resident artifacts that would be lost upon a reboot or power-down, providing the best foundation for a successful analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Take a forensic image of the hard drive using a hardware write-blocker.
Why it's wrong here
Disk imaging is a time-consuming process that often requires a system shutdown or at least significantly alters the system's state. It is not the first step in a live response, as volatile evidence stored in memory (RAM) would be lost or modified during this long acquisition process.
- ✓
Capture volatile data, including process listings, open handles, and network connections.
Why this is correct
Capturing volatile data is the priority because it is the most ephemeral evidence. By using memory acquisition tools, you can identify what the attacker is doing in real-time, such as open network sockets or injected threads, which are essential for understanding the scope of the current incident.
- ✗
Power down the system immediately to preserve the current state.
Why it's wrong here
Powering down a system is the most destructive action an investigator can take. It results in the immediate loss of all volatile memory (RAM), where the most critical evidence of modern cyberattacks resides. This action should only be taken as a last resort for containment in extreme scenarios.
- ✗
Run an antivirus scan to identify and delete the malicious process.
Why it's wrong here
Running antivirus tools during an investigation modifies the system state and can inadvertently delete evidence or alert the attacker to your discovery. The goal of incident response is to analyze and contain, not to blindly execute antivirus scans that could destroy the evidence needed for a proper investigation.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.