
GIAC Certified Incident Handler
Domain 2Objective 3
Endpoint Attack and Pivoting GCIH Practice Questions (Page 1)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 1–5
- 1
During an incident, you notice that a compromised workstation is making connections to an internal database server on a port that is not used by any application in your environment. The database server is not normally accessed from that workstation. What does this indicate?
Select an answer first - 2
A help desk ticket reports that multiple users are receiving phishing emails with a malicious attachment. One user has already opened the attachment, and the EDR shows that the resulting malware is attempting to download additional payloads. Which step should you take FIRST in the incident response process?
Select an answer first - 3
You have identified that an attacker is using a compromised host to pivot through the network. You need to stop the pivoting, but you also want to maintain visibility into the attacker's activities for further investigation. Which strategy best achieves both goals?
Select an answer first - 4
During an incident involving pivoting, which action is most effective in preventing the attacker from using a compromised host to reach other systems?
Select an answer first - 5
A user reports that their workstation is infected with ransomware. The ransomware has encrypted local files and is attempting to spread to network shares. You need to contain the incident. Which action should you take FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.