Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 1)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 1–5

  1. 1application · medium

    A malware sample is found to check if it is running in a virtual machine by looking for specific hardware identifiers. If it detects a VM, it exits without performing any malicious actions. Which evasion technique is this?

    Select an answer first
  2. 2application · medium

    A forensic investigator finds that a compromised server has a new service installed that is set to start automatically. The service binary is located in a temporary directory. Which post-exploitation technique is most clearly indicated?

    Select an answer first
  3. 3expert · hard

    An incident responder is investigating a breach where the attacker used a legitimate remote administration tool to move laterally. The tool's traffic is encrypted and uses standard ports. The responder has access to endpoint logs and network flow logs. Which detection strategy would be most effective in identifying the lateral movement?

    Select an answer first
  4. 4expert · hard

    A malware analyst is analyzing a sample that uses a technique to load a DLL into memory without writing it to disk. The DLL is encrypted and only decrypted in memory. The analyst wants to detect this behavior on a live system. Which detection strategy would be most effective?

    Select an answer first
  5. 5application · medium

    A security team is investigating a malware sample that uses a custom packer to compress and encrypt its payload. When the sample is executed in a sandbox, it detects that it is running in a virtualized environment and exits without unpacking. Which evasion technique is the malware using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.