
GIAC Certified Incident Handler
Domain 2Objective 2
Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 4)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 16–20
- 16
An incident responder discovers that an attacker is using SSH tunneling to exfiltrate data from a compromised server. The SSH connection is established from the server to an external IP on port 22, and the tunnel is carrying internal database traffic. Which containment action is most effective while preserving evidence?
Select an answer first - 17
A security analyst is investigating a host that is suspected of using steganography to hide data in image files. Which host-based artifact would provide the strongest evidence of steganography tool usage?
Select an answer first - 18
Which action is most effective for eradicating a covert communications tool from an endpoint?
Select an answer first - 19
During incident response, you find a process named 'winword.exe' running on a server that does not have Microsoft Office installed. The process has a network connection to an external IP on port 53, and the file's hash matches a known covert tool. The server is a critical application server that cannot be taken offline. Which action best balances containment and evidence preservation?
Select an answer first - 20
An organization's firewall logs show a workstation making frequent HTTPS connections to a known file-sharing domain. Endpoint logs show a process named 'update.exe' running from the user's AppData folder. The process has not been seen before, and the user denies installing any software. Which set of indicators most strongly suggests a covert communications tool?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.