Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 6)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 26–30

  1. 26foundation · easy

    A security analyst observes multiple failed logon attempts followed by a successful logon from the same source IP to a domain controller, and then the source IP immediately connects to other workstations using the same credentials. This pattern is most indicative of which post-exploitation activity?

    Select an answer first
  2. 27application · medium

    An organization has enabled PowerShell script block logging and transcription. During a review, an analyst finds a script that uses base64-encoded strings and invokes the .NET classes to download and execute a payload. Which detection strategy would best identify this activity in the logs?

    Select an answer first
  3. 28expert · hard

    A malware analyst is examining a sample that uses a technique to check if it is running in a sandbox by looking for the presence of specific DLLs and checking the number of processors. If the DLLs are present or the processor count is low, the malware exits. Which evasion technique is the malware using, and what is the best way to detect it?

    Select an answer first
  4. 29foundation · easy

    An analyst notices that a service named 'Windows Update Service' has been created on a compromised host, and its binary path points to a file in the user's Temp directory. This is most likely an indicator of which post-exploitation activity?

    Select an answer first
  5. 30application · medium

    An incident responder is examining a malicious executable that uses a packer to compress and encrypt its code. When the executable runs, it unpacks itself in memory. Which evasion technique is the executable using?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.