nerdexam
GIAC

GCIH · Question #502

The Kratla Company deploys laptops running Windows or Mac OS to their employees, who connect via VPN. What tool can the incident response team use to centrally gather critical logs from these hosts…

The correct answer is D. GRR Rapid Response. GRR Rapid Response is the correct tool because it is an agent-based remote live forensics platform that supports centralized log collection and volatile data analysis across both Windows and macOS hosts.

Incident Response & Cyber Kill Chain

Question

The Kratla Company deploys laptops running Windows or Mac OS to their employees, who connect via VPN. What tool can the incident response team use to centrally gather critical logs from these hosts as well as perform remote analysis of volatile data?

Options

  • ASysinternals Suite
  • BEyeWitness
  • CPowershell Empire
  • DGRR Rapid Response

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    5% (2)
  • D
    91% (39)

Why each option

GRR Rapid Response is the correct tool because it is an agent-based remote live forensics platform that supports centralized log collection and volatile data analysis across both Windows and macOS hosts.

ASysinternals Suite

Sysinternals Suite is a collection of Windows-only utilities that must be run locally or via PsExec; it provides no centralized multi-host collection capability and does not support macOS.

BEyeWitness

EyeWitness is a reconnaissance tool for capturing screenshots of web interfaces and harvesting HTTP headers, not a platform for incident response log collection or volatile data analysis.

CPowershell Empire

PowerShell Empire is a post-exploitation command-and-control framework used offensively by attackers, not a legitimate incident response tool for authorized log and volatile data collection.

DGRR Rapid ResponseCorrect

GRR Rapid Response, developed by Google, deploys lightweight agents to endpoints and provides a centralized web interface for collecting artifacts, logs, and volatile data such as running processes and memory. It supports both Windows and macOS, making it purpose-built for the cross-platform, VPN-connected enterprise scenario described, unlike tools that are single-OS or lack centralized orchestration.

Concept tested: Remote live forensics tool selection for cross-platform IR

Source: https://grr-doc.readthedocs.io/en/latest/

Topics

#GRR Rapid Response#remote forensics#volatile data collection#centralized logging

Community Discussion

No community discussion yet for this question.

Full GCIH Practice