
GIAC Certified Incident Handler
Domain 2Objective 1
Detecting Evasive and Post-Exploitation Techniques GCIH Practice Questions (Page 8)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
4concepts
Questions 36–37
- 36
An incident responder is investigating a compromised server where the attacker created a new service that runs a binary from a temp directory. The service is configured to start automatically. Which post-exploitation technique is most directly indicated, and which detection strategy would best identify it?
Select an answer first - 37
A malware analyst is analyzing a sample that uses a technique to detect if it is being debugged. The malware checks the PEB (Process Environment Block) for the BeingDebugged flag. Which evasion technique is this?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.