Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 2Objective 3

Endpoint Attack and Pivoting GCIH Practice Questions (Page 6)

Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 26–30

  1. 26application · medium

    An attacker has compromised a public-facing web server and is using it to scan internal IP ranges. The internal scans are originating from the web server's IP address. What is this an example of?

    Select an answer first
  2. 27expert · hard

    You are responding to an incident where a workstation is infected with ransomware that encrypts files on local drives and mapped network shares. The ransomware is actively spreading to other workstations via SMB. You need to contain the spread while preserving evidence for investigation. Which action is the best first step?

    Select an answer first
  3. 28application · medium

    A help desk technician receives a phishing email that appears to be from the CEO, asking for urgent wire transfer. The technician clicks the link and enters their domain credentials on a fake login page. Later, the security team sees the technician's account attempting to log into a file server from an unfamiliar IP. What should be the FIRST containment step?

    Select an answer first
  4. 29expert · hard

    During an incident, you identify that an attacker is using a compromised domain controller to pivot to other servers. You need to stop the pivoting, but the domain controller is critical for authentication and cannot be taken offline during business hours. Which approach best balances containment and operational continuity?

    Select an answer first
  5. 30foundation · easy

    Which incident response phase involves removing the root cause of the endpoint attack, such as deleting malware and closing the vulnerability that was exploited?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.