Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 4)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 16–20

  1. 16application · medium

    A malware analyst is examining a suspicious executable that, when run, checks for the presence of a debugger and then sleeps for a random amount of time before executing its payload. Which evasion technique is the malware using?

    Select an answer first
  2. 17application · medium

    A security analyst is reviewing a suspicious document that contains a macro. The macro uses a series of conditional statements to check the system time and only executes the payload if the time is between 9 AM and 5 PM. Which evasion technique is the macro using?

    Select an answer first
  3. 18foundation · easy

    An analyst observes a malicious script that contains a long string of hexadecimal characters. When decoded, the string reveals the actual payload. Which evasion technique is the attacker primarily using?

    Select an answer first
  4. 19expert · hard

    A security team is investigating a malware sample that uses a technique to hide its network traffic by blending in with legitimate HTTP traffic. The malware uses standard HTTP headers and mimics a popular web application's API calls. Which detection strategy would be most effective in identifying this traffic?

    Select an answer first
  5. 20application · medium

    A SOC analyst is investigating a potential breach and notices that a user account has been added to the Domain Admins group. The account was created recently and has never logged in. Which detection strategy would have most likely alerted the analyst to this activity?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.