Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 5)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 21–25

  1. 21application · medium

    An analyst is reviewing a suspicious PowerShell script that uses a variable to store a string, then reverses the string and executes it. What is the primary purpose of this technique?

    Select an answer first
  2. 22application · medium

    An analyst is reviewing network logs and notices that a compromised host is making connections to an internal file server using SMB on port 445, and the file server is then making connections to an external IP address. Which detection strategy would best identify this as lateral movement?

    Select an answer first
  3. 23expert · hard

    An organization has implemented a security information and event management (SIEM) system that collects logs from firewalls, endpoints, and authentication servers. During an investigation, an analyst finds that an attacker used a compromised account to access a file server and then used that server to access a database server. The analyst wants to detect this lateral movement in the SIEM. Which detection strategy would be most effective?

    Select an answer first
  4. 24foundation · easy

    During incident response, you find a PowerShell script that uses the .NET `System.IO.Compression` namespace to decompress a Base64-encoded string before executing it. Which evasion technique is being used?

    Select an answer first
  5. 25application · medium

    A malware analyst is analyzing a binary that uses a custom algorithm to transform its code at runtime, making each instance of the malware unique. Which evasion technique is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.