Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 1

Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 7)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)

37questions here
8free pages
4concepts

Questions 31–35

  1. 31application · medium

    A SOC analyst is reviewing logs after a suspected breach. The analyst notices that a standard user account ran a PowerShell command that created a new local user and added it to the Administrators group. The command was encoded in Base64. Which detection strategy would have most likely alerted the analyst to this activity earlier?

    Select an answer first
  2. 32expert · hard

    An organization has a policy that requires all administrative access to be performed through a jump host. During an investigation, an analyst finds that a server was accessed directly from a workstation, bypassing the jump host. The analyst has access to authentication logs and network flow logs. Which detection strategy would best identify this policy violation?

    Select an answer first
  3. 33foundation · easy

    While analyzing a malware sample in a sandbox, you notice that the malware checks the system's uptime and delays execution if the uptime is less than 10 minutes. This behavior is an example of which evasion tactic?

    Select an answer first
  4. 34foundation · easy

    A malware sample is observed to use Windows API calls to allocate memory with read-write-execute permissions, then write a second-stage payload to that memory and execute it directly. This behavior is primarily designed to evade which type of detection?

    Select an answer first
  5. 35application · medium

    A security analyst notices that a workstation is making repeated outbound HTTPS connections to a newly-registered domain. The endpoint protection tool shows no alerts, and the traffic is allowed by the firewall because it uses port 443. The analyst suspects the traffic is malicious but cannot see the payload. Which detection strategy would most effectively confirm the malicious activity in this situation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.