GSEC Malicious Code and Exploit Mitigation Practice Question
An administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?
⚠ Common exam trap
Candidates often suggest 'rebooting the host' or 'running a virus scan'. These actions wipe volatile memory, destroying critical forensic evidence before the incident responder can analyze the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the infected host from the network via switch port shutdown.
Isolating the host from the network preserves the integrity of the volatile memory and prevents command-and-control communication. In security operations, containment precedes deep analysis to ensure the adversary cannot execute further malicious actions or delete artifacts. This approach balances the need for forensic readiness with the urgent requirement to stop ongoing lateral movement or data exfiltration, adhering to standard GIAC incident response methodologies regarding host-based threat containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately terminate the process using the task manager.
Why it's wrong here
Killing the process immediately destroys volatile data stored in RAM, such as network connections, decrypted payloads, and injection artifacts. This action prevents a full forensic analysis, which is critical for understanding the root cause and identifying additional indicators of compromise that may exist elsewhere in the environment.
- ✗
Perform a full system backup to an external network share.
Why it's wrong here
Backing up a compromised system can replicate the malicious code to the backup environment. Furthermore, the transfer process generates network traffic that might trigger the malware's anti-forensics capabilities, potentially causing it to self-delete or encrypt files, further complicating the investigation and putting secondary systems at significant risk.
- ✓
Isolate the infected host from the network via switch port shutdown.
Why this is correct
Network isolation successfully severs the communication channel between the malware and the attacker's command-and-control server. This containment step halts data exfiltration and remote command execution while leaving the host powered on, allowing for the secure collection of volatile memory and disk images for post-incident forensic investigation.
- ✗
Run a full scan with the local antivirus engine.
Why it's wrong here
Local antivirus solutions are often bypassed by custom or advanced persistent threats using obfuscation. Running the scanner modifies file access times and potentially overwrites memory space, destroying critical evidence. In an incident response scenario, scanners should only be used after forensic artifacts have been safely captured and preserved.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.