Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 2

Detecting Exploitation and Covert Communications Tools GCIH Practice Questions (Page 9)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
6concepts

Questions 41–42

  1. 41expert · hard

    A SOC analyst is investigating an alert about a workstation communicating with a known malicious IP over port 53. The firewall log shows the traffic, but the DNS server logs do not show any corresponding DNS queries for that IP. The workstation's EDR shows no malicious processes. Which conclusion is most likely?

    Select an answer first
  2. 42application · medium

    A network analyst observes that a workstation is sending DNS queries to an external server for long, random subdomains under a single domain, such as 'a3f9c2.example.com'. The queries occur at regular intervals and the responses are larger than typical DNS responses. No other workstations show this pattern. What does this behavior most likely indicate?

    Select an answer first
Finished these 2 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GCIH

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.