
GIAC Certified Incident Handler
Domain 2Objective 2
Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 5)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 21–25
- 21
Which scenario best illustrates the value of log correlation?
Select an answer first - 22
Why is correlating logs from multiple sources important in incident detection?
Select an answer first - 23
A security analyst is examining network traffic and sees a series of HTTP requests to a website that hosts images. The requests include a parameter that contains a long string of base64-encoded data. The images themselves appear normal when viewed. Which technique is most likely being used?
Select an answer first - 24
Which network traffic anomaly is most indicative of a DNS tunneling covert channel?
Select an answer first - 25
An organization's IDS alerts on outbound traffic from a database server to an external IP on port 53 using DNS queries with unusually long subdomains. The firewall logs show the same pattern. Endpoint logs show a process named 'dnsupdate.exe' running from the system's Temp directory. Which action should the incident responder take to confirm the covert channel?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.