
GIAC Certified Incident Handler
Domain 2Objective 3
Endpoint Attack and Pivoting GCIH Practice Questions (Page 8)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 36–40
- 36
Which endpoint detection and response (EDR) capability goes beyond traditional antivirus by collecting and correlating endpoint telemetry to detect and investigate advanced threats?
Select an answer first - 37
During an incident, you discover that an attacker has compromised a jump server and is using it to RDP into multiple internal servers. You need to stop the pivoting while preserving evidence for forensic analysis. Which action best achieves both goals?
Select an answer first - 38
Which of the following is a strategy to stop pivoting during an incident?
Select an answer first - 39
A user receives an email with an attachment that, when opened, launches a PowerShell script that downloads and executes a payload. The antivirus does not detect the payload. Which detection method would be MOST effective at identifying this attack?
Select an answer first - 40
Your EDR solution is generating a high volume of alerts for a single workstation, but most are false positives. You need to reduce noise while still detecting real attacks. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.