
GIAC Certified Incident Handler
Domain 2Objective 2
Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 8)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
6concepts
Questions 36–40
- 36
Which of the following is a common host-based indicator of exploitation?
Select an answer first - 37
An incident responder has confirmed that a server is using a covert channel over HTTP to communicate with a command-and-control server. The responder needs to contain the threat while minimizing disruption to legitimate web services hosted on the same server. Which action best achieves this?
Select an answer first - 38
An incident responder is analyzing a host that is suspected of using a covert communications tool. The host has a process named 'svchost.exe' running from the System32 directory, which is normal. However, the process has a network connection to an external IP on port 443, and the user has no reason to have such a connection. The process's command line includes a suspicious flag. Which action would best confirm whether this is a covert tool?
Select an answer first - 39
An incident responder is analyzing a compromised Windows server. The responder finds a new service named 'UpdateService' that is set to auto-start. The service binary is located in 'C:\Windows\Temp\update.exe'. The server's security logs show that the service was created at the same time as a successful logon from a remote IP. The file's hash is not in the vendor's database. Which action is most appropriate to confirm the service is malicious?
Select an answer first - 40
An organization's IDS alerts on a series of HTTP requests to a web server that contain a long string of base64-encoded data in the URL parameter. The web server logs show the requests originated from a single internal IP that is not a known admin workstation. The requests are interspersed with normal-looking requests to the same server. What is the best next step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.