Courseiva

GSEC Incident Handling and Response Practice Question

A junior analyst at a healthcare provider receives a call from the help desk: a radiology workstation is behaving erratically and displaying a ransom note. The analyst immediately opens a remote session, logs in with domain administrator credentials, and begins deleting suspicious files in the user's startup folder. The workstation is still powered on and connected to the network. Which incident handling principle did the analyst MOST directly violate?

⚠ Common exam trap

The trap here is assuming that immediate deletion of malicious files constitutes effective response, when in fact containment must occur first to prevent spread and preserve evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containment must precede eradication to prevent the threat from spreading to other systems.

The analyst began eradication (deleting files) while the compromised workstation remained powered on and connected to the network. This violates the containment-first principle: without isolating the system, malware can spread laterally, communicate with command-and-control, or re-infect. Proper incident handling isolates the host—via network disconnection or VLAN isolation—before removing malicious artifacts. Containment limits damage and preserves evidence for later analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Containment must precede eradication to prevent the threat from spreading to other systems.

    Why this is correct

    The analyst deleted files before containing the workstation, leaving it networked and allowing the malware to spread or communicate. Proper sequence is containment then eradication. Deleting files with elevated credentials also risks tipping off the attacker and destroying volatile evidence. This is the most direct violation of the containment-first principle.

  • ✗

    The analyst used domain administrator credentials, which violates the principle of least privilege.

    Why it's wrong here

    Using domain administrator credentials on a potentially compromised system is risky and could expose those credentials, but the most direct violation is the failure to contain the workstation before eradication. Least privilege is a supporting principle; the primary incident handling error is the order of operations, allowing potential spread.

  • ✗

    The analyst failed to preserve the chain of custody for the workstation's hard drive.

    Why it's wrong here

    Chain of custody applies to evidence collected for legal proceedings, typically involving proper documentation and handling. While the analyst's actions may compromise evidence, the immediate and most direct violation is failing to contain the system before attempting eradication. Chain of custody is a downstream concern and not the primary principle breached here.

  • ✗

    The analyst should have escalated to senior management before taking any action on the workstation.

    Why it's wrong here

    Escalation is important, but incident response procedures often authorize initial containment actions by first responders. The critical error is not the lack of escalation but the sequence of actions: deleting files while the system remained networked. Escalation alone would not have prevented the spread; containment would have.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.