
GIAC Certified Incident Handler
Domain 2Objective 2
Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 3)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 11–15
- 11
Which technique is commonly used by covert communications tools to bypass network security controls?
Select an answer first - 12
During incident response, you confirm that an attacker is using a covert channel over HTTPS to a command-and-control server. The affected workstation is a developer's machine that is currently in use. Which containment action is most appropriate to minimize disruption while stopping the covert channel?
Select an answer first - 13
An organization's IDS alerts on outbound DNS queries with high entropy subdomains from a single workstation. The firewall logs show the same workstation making these queries to a domain that was registered three days ago. Endpoint logs show a process named 'svchost.exe' running from the user's Temp directory. The user is a marketing employee who does not typically use DNS for anything other than web browsing. Which conclusion is most justified?
Select an answer first - 14
During a forensic investigation, an analyst finds a file named 'photo.jpg' in a user's directory that is 5 MB in size. The user has no other large image files. The file's creation time matches the time of a suspected data exfiltration event. Which action would best confirm whether the file contains hidden data?
Select an answer first - 15
An organization discovers that an attacker is using a covert channel over HTTPS to exfiltrate data from a server. The server is a legacy system that cannot be patched and is required for a critical business process. The attacker's IP is dynamic and changes frequently. Which response strategy is most effective in the long term?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.