
GIAC Certified Incident Handler
Domain 2Objective 3
Endpoint Attack and Pivoting GCIH Practice Questions (Page 4)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 16–20
- 16
During an incident, you observe that an attacker is using a compromised workstation to connect to multiple internal servers using the same credentials. The credentials belong to a service account that has administrative rights on several servers. You need to stop the pivoting while minimizing disruption to business operations. Which action is the best first step?
Select an answer first - 17
How does pivoting facilitate lateral movement in a network attack?
Select an answer first - 18
In the context of network attacks, what does 'pivoting' refer to?
Select an answer first - 19
You are responding to an incident where an attacker has compromised a domain controller and is using it to pivot to other servers. You need to stop the pivoting while preserving the ability to investigate the attacker's activities. Which action best achieves this?
Select an answer first - 20
A user reports that their computer is infected after they plugged in a USB drive found in the parking lot. The EDR shows that the USB drive contained an autorun script that executed when inserted. Which endpoint attack vector was used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.