GSEC Incident Handling and Response Practice Question
Exhibit
Log Entry: 2023-10-12 14:22:01, SRC: 192.168.1.50, DST: 10.0.0.5, CMD: 'powershell.exe -Enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsA...'
Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?
⚠ Common exam trap
Candidates often suggest running a malware scan or deleting the script, which allows the attacker to maintain C2 connectivity while the responder works, failing to prioritize immediate containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the workstation from the network
The exhibit shows base64 encoded PowerShell execution, commonly used for malicious script downloads. Immediate containment requires isolating the endpoint from the network to prevent further outbound connections to C2 servers. By severing the network connection, responders prevent the attacker from executing additional instructions, exfiltrating data, or establishing secondary persistence mechanisms while the forensic investigation proceeds offline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the workstation immediately
Why it's wrong here
Rebooting will clear volatile memory, destroying critical evidence such as the decrypted command string or active socket connections. Forensic best practices dictate that the system state must be preserved for analysis before any destructive actions like reboots are performed, as memory artifacts are essential for identifying the payload.
- ✓
Isolate the workstation from the network
Why this is correct
Isolating the host prevents the attacker from issuing further commands or exfiltrating data, effectively containing the threat. By cutting the network path, you stop the malicious script from reaching its destination without destroying the volatile memory evidence needed to identify the full scope of the attack activity.
- ✗
Delete the PowerShell process
Why it's wrong here
Terminating a process is an insufficient containment measure because the attacker may have already established other persistence mechanisms or secondary backdoors. The malicious process could also be a child of another service, leading to immediate respawning. Full network isolation is required to ensure the host is contained.
- ✗
Update the antivirus definitions
Why it's wrong here
Updating antivirus is a long-term remediation step, not an immediate containment action. During an active incident involving encoded command execution, the priority is to stop the adversary's access. Relying on antivirus signatures is reactive and unlikely to stop a custom script that is already running in memory.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.