(GCIH) GIAC Experienced Incident Handler Practice Test
GCIH Network Forensics & Malware Analysis
What is the first step in network forensics after detecting an incident?
Select your answer
A
Begin remediation efforts immediately.
B
Preserve evidence and create an incident timeline
C
Start analyzing the incident data.
D
Report the incident to external authorities.
Hint