
GIAC Certified Incident Handler
Domain 6Objective 1
Integrating LLMs with Offensive Operations GCIH Practice Questions (Page 5)
Part of the Emerging Technologies and Offensive Operations domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
Questions 21–25
- 21
A security engineer is designing an automated reconnaissance tool that uses an LLM to parse and summarize public data about a target organization. The tool will run continuously and feed summaries into a reporting dashboard. Which integration approach is most appropriate?
Select an answer first - 22
Which of the following is a typical prompt injection technique used to leak sensitive information from an LLM?
Select an answer first - 23
How can an LLM be used to automate reconnaissance in offensive operations?
Select an answer first - 24
A security analyst is using an LLM to automate the collection of threat intelligence from public sources. The analyst wants to ensure the LLM does not inadvertently leak sensitive information about their own organization. Which practice is most important?
Select an answer first - 25
During an incident response, a defender finds a blog post that appears to be written by the attacker, but the technical details are inaccurate and inconsistent with the actual attack. What is the most likely purpose of this post?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.