
GIAC Certified Incident Handler
Domain 2Objective 3
Endpoint Attack and Pivoting GCIH Practice Questions (Page 9)
Part of the Attack Techniques and Detection domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~17–29 in this domain), expect 6–10 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 41–44
- 41
You are investigating a breach where an attacker has been using a compromised service account to authenticate to multiple servers. The account has legitimate access to a few servers, but logs show it is also accessing servers it has never accessed before. You need to detect the full scope of the pivoting. Which approach is most effective?
Select an answer first - 42
Which of the following is a common indicator of pivoting activity on a network?
Select an answer first - 43
During an incident, you notice that a compromised workstation is making repeated connections to an internal file server using credentials that were recently used on another compromised host. What does this pattern most likely indicate?
Select an answer first - 44
Which of the following best describes a common endpoint attack vector where an attacker tricks a user into opening a malicious attachment that then installs malware?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.