
GIAC Certified Incident Handler
Domain 6Objective 1
Integrating LLMs with Offensive Operations GCIH Practice Questions (Page 1)
Part of the Emerging Technologies and Offensive Operations domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
Questions 1–5
- 1
Which of the following is a common use of LLMs in offensive operations for payload generation?
Select an answer first - 2
A security analyst discovers that an internal LLM-based chatbot, connected to a customer database, has been tricked into revealing customer PII by a user who injected a prompt that overrode the system's instructions. Which defensive countermeasure would most directly prevent this type of attack?
Select an answer first - 3
A red-team operator is building a tool that uses an LLM to automate initial reconnaissance. The tool will query public APIs, summarize findings, and then generate follow-up queries. The operator wants to minimize the risk of the LLM being manipulated by malicious data encountered during recon. Which approach best reduces this risk?
Select an answer first - 4
What is a key method to detect offensive use of LLMs in an organization?
Select an answer first - 5
How can an attacker exploit LLM hallucinations to mislead defenders?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.