nerdexam
ExamsGCIHQuestions#180
GIAC

GCIH · Question #180

GCIH Question #180: Real Exam Question with Answer & Explanation

Sign in or unlock GCIH to reveal the answer and full explanation for question #180. The question stem and answer options stay visible for context.

Incident Response & Cyber Kill Chain

Question

Adam works as an Incident Handler for Umbrella Inc. He is informed by the senior authorities that the server of the marketing department has been affected by a malicious hacking attack. Supervisors are also claiming that some sensitive data are also stolen. Adam immediately arrived to the server room of the marketing department and identified the event as an incident. He isolated the infected network from the remaining part of the network and started preparing to image the entire system. He captures volatile data, such as running process, ram, and network connections. Which of the following steps of the incident handling process is being performed by Adam?

Options

  • ARecovery
  • BEradication
  • CIdentification
  • DContainment

Unlock GCIH to see the answer

You've previewed enough free GCIH questions. Unlock GCIH for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#IR phases#containment#volatile data collection#incident response process
Full GCIH Practice