Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 2

Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 1)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 1–5

  1. 1application · medium

    An endpoint detection and response (EDR) alert shows that a process named 'notepad.exe' has a network connection to an external IP on port 53. The process is running from 'C:\Users\Public\Documents\notepad.exe' instead of the standard Windows directory. The file's digital signature is invalid. What does this combination of indicators most likely suggest?

    Select an answer first
  2. 2application · medium

    During incident response, an analyst finds a process named 'svch0st.exe' running from the user's Temp directory. The process has an established TCP connection to an external IP on port 443, and the parent process is a document reader. Which finding most strongly indicates that this is a covert communications tool rather than a legitimate process?

    Select an answer first
  3. 3application · medium

    A security analyst notices a server that normally communicates with a few known update repositories is now sending small, periodic HTTPS packets to a single IP address in a foreign country at 3-minute intervals, every hour, even at night. The server's endpoint protection shows no alerts, and the packets are encrypted. Which action is most appropriate to confirm whether this is covert communications?

    Select an answer first
  4. 4application · medium

    An organization's IDS alerts on outbound DNS queries containing long subdomains with high entropy to a domain that was only registered last week. The firewall logs show the same workstation making these queries every few minutes. Endpoint logs show a process named 'winupdate.exe' in the user's AppData folder that makes DNS queries. Which action should the incident responder take first?

    Select an answer first
  5. 5foundation · easy

    Which file artifact is commonly associated with covert communications tools?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.