Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 2

Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 8)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 36–40

  1. 36foundation · easy

    Which of the following is a common host-based indicator of exploitation?

    Select an answer first
  2. 37application · medium

    An incident responder has confirmed that a server is using a covert channel over HTTP to communicate with a command-and-control server. The responder needs to contain the threat while minimizing disruption to legitimate web services hosted on the same server. Which action best achieves this?

    Select an answer first
  3. 38expert · hard

    An incident responder is analyzing a host that is suspected of using a covert communications tool. The host has a process named 'svchost.exe' running from the System32 directory, which is normal. However, the process has a network connection to an external IP on port 443, and the user has no reason to have such a connection. The process's command line includes a suspicious flag. Which action would best confirm whether this is a covert tool?

    Select an answer first
  4. 39expert · hard

    An incident responder is analyzing a compromised Windows server. The responder finds a new service named 'UpdateService' that is set to auto-start. The service binary is located in 'C:\Windows\Temp\update.exe'. The server's security logs show that the service was created at the same time as a successful logon from a remote IP. The file's hash is not in the vendor's database. Which action is most appropriate to confirm the service is malicious?

    Select an answer first
  5. 40application · medium

    An organization's IDS alerts on a series of HTTP requests to a web server that contain a long string of base64-encoded data in the URL parameter. The web server logs show the requests originated from a single internal IP that is not a known admin workstation. The requests are interspersed with normal-looking requests to the same server. What is the best next step?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.