Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 2

Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 3)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 11–15

  1. 11foundation · easy

    Which technique is commonly used by covert communications tools to bypass network security controls?

    Select an answer first
  2. 12application · medium

    During incident response, you confirm that an attacker is using a covert channel over HTTPS to a command-and-control server. The affected workstation is a developer's machine that is currently in use. Which containment action is most appropriate to minimize disruption while stopping the covert channel?

    Select an answer first
  3. 13expert · hard

    An organization's IDS alerts on outbound DNS queries with high entropy subdomains from a single workstation. The firewall logs show the same workstation making these queries to a domain that was registered three days ago. Endpoint logs show a process named 'svchost.exe' running from the user's Temp directory. The user is a marketing employee who does not typically use DNS for anything other than web browsing. Which conclusion is most justified?

    Select an answer first
  4. 14application · medium

    During a forensic investigation, an analyst finds a file named 'photo.jpg' in a user's directory that is 5 MB in size. The user has no other large image files. The file's creation time matches the time of a suspected data exfiltration event. Which action would best confirm whether the file contains hidden data?

    Select an answer first
  5. 15expert · hard

    An organization discovers that an attacker is using a covert channel over HTTPS to exfiltrate data from a server. The server is a legacy system that cannot be patched and is required for a critical business process. The attacker's IP is dynamic and changes frequently. Which response strategy is most effective in the long term?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.