GCFA GIACCertified Forensics Analyst Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

An advanced persistent threat (APT) campaign targeting a multinational financial institution has been detected. Initial indicators suggested a focus on exfiltrating customer PII. However, during the forensic examination of compromised systems, unexpected artifacts point towards the APT also attempting to disrupt critical backend financial transaction processing systems, a completely different objective. The incident response team\'s initial containment strategy was based solely on preventing PII exfiltration.

Considering the evolving understanding of the threat\'s scope and intent, which of the following actions best demonstrates the analyst\'s adaptability and flexibility in this critical situation?

Immediately revise the containment strategy to include blocking outbound traffic associated with financial transaction protocols and re-prioritize artifact analysis towards identifying the mechanism of disruption, while informing stakeholders of the broadened scope.
Continue focusing on the PII exfiltration vector as per the initial mandate, documenting the new findings as a separate, secondary investigation to maintain focus.
Halt all investigative activities until a new, comprehensive incident response plan can be drafted and approved by senior management, ensuring all potential vectors are addressed.
Delegate the investigation of the transaction processing disruption to a separate team without direct oversight, allowing the primary team to continue its original objective.

About the GCFA GIACCertified Forensics Analyst Certification

These free practice questions are designed to help you assess your readiness for the GCFA GIACCertified Forensics Analyst exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.