Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 2)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 6–10

  1. 6expert · hard

    A malware analyst is examining a sample that uses a custom algorithm to generate domain names based on the current date. The malware attempts to connect to these domains to receive commands. The analyst wants to detect the malware's command-and-control activity in network logs. Which detection strategy would be most effective?

    Select an answer first
  2. 7application · medium

    A security analyst notices that a workstation is making repeated DNS queries for subdomains that look like random hex strings under a domain that is not on any allowlist. The strings decode to ASCII when converted from hex. The analyst suspects the traffic is part of a command-and-control channel. Which detection strategy is most effective for confirming this behavior?

    Select an answer first
  3. 8application · medium

    During an incident, a forensic analyst finds a scheduled task on a compromised server that runs a PowerShell script every hour. The script downloads a small executable from a file-sharing site and executes it in memory. The analyst also finds that the server's local administrator account password was changed. Which two post-exploitation techniques are most clearly indicated by these findings?

    Select an answer first
  4. 9application · medium

    A security team wants to detect an attacker who is using a legitimate remote administration tool (RAT) like TeamViewer to control a compromised host. Which detection strategy would be most effective?

    Select an answer first
  5. 10expert · hard

    An organization has a mature SIEM that ingests Windows Event Logs, including Sysmon, and network flow logs. During an investigation, an analyst finds that a compromised host is using WMI to execute commands on a remote server. The commands are obfuscated and the remote server is not showing any signs of compromise in its own logs. Which detection strategy would best uncover this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.