Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 2

Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 2)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security operations center (SOC) analyst sees a firewall log entry showing outbound traffic from a database server to an external IP on port 22. The IDS shows no alert for this traffic, and the endpoint agent on the database server shows no unusual processes. However, the database server is not supposed to initiate SSH connections. What should the analyst do first?

    Select an answer first
  2. 7foundation · easy

    What is the primary purpose of using steganography in covert communications?

    Select an answer first
  3. 8application · medium

    A security analyst is reviewing a packet capture and notices a series of TCP connections to an external IP on port 443, but the TLS handshake fails and the payloads contain plaintext data that looks like base64. The connections occur in bursts every few minutes. Which indicator is most consistent with a covert channel?

    Select an answer first
  4. 9application · medium

    During incident response, you find a process named 'svch0st.exe' running on a compromised Windows workstation. The process has an open TCP connection to an external IP on port 443, and the file's hash matches a known covert tunneling tool. The workstation is not a server and does not normally initiate outbound HTTPS connections. Which immediate action is most appropriate?

    Select an answer first
  5. 10expert · hard

    A network analyst is reviewing traffic and sees a series of HTTP requests to a web server that hosts a legitimate file-sharing service. The requests include a parameter that contains a long string of base64-encoded data. The responses are normal images. The analyst suspects steganography. Which additional finding would most strongly support this hypothesis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.