Courseiva

GSEC Incident Handling and Response Practice Question

An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?

⚠ Common exam trap

The trap here is assuming that copying binaries to external media is the first step, when volatile live state must be captured before less perishable artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Order of volatility, by collecting live system state before it changes.

The order of volatility directs responders to collect the most perishable evidence first, such as network connections, running processes, and kernel modules, before they change or disappear. By gathering this live state before copying static binaries, the analyst is prioritizing volatile data. Chain of custody, least privilege, and defense in depth address different concerns and do not describe this collection sequence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Chain of custody, by documenting each piece of evidence collected.

    Why it's wrong here

    Chain of custody concerns documenting who handled evidence, when, and how to maintain its integrity for legal use. The scenario describes collecting volatile data, not logging custody transfers. While chain of custody matters, it does not explain why the analyst prioritized live state over copying binaries, so it is not the principle being applied here.

  • ✓

    Order of volatility, by collecting live system state before it changes.

    Why this is correct

    The analyst is capturing volatile data such as network connections, processes, and kernel modules while the system is live, before it changes or is lost. This directly follows the order of volatility principle, which prioritizes the most perishable evidence first. Running the script before copying binaries reflects that prioritization, making this the correct principle.

  • ✗

    Least privilege, by limiting the analyst's access to system resources.

    Why it's wrong here

    Least privilege restricts user and process permissions to the minimum necessary. The scenario does not describe permission restrictions; it describes the sequence of evidence collection. The analyst's choice to gather volatile data first is unrelated to access control, so least privilege is not the principle at work in this situation.

  • ✗

    Defense in depth, by using multiple tools to examine the system.

    Why it's wrong here

    Defense in depth layers security controls so that failure of one does not compromise the whole. The analyst is not deploying layered controls; they are sequencing evidence collection. The decision to capture volatile state before static binaries reflects the order of volatility, not a layered defensive strategy, so this option does not fit the scenario.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.