Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 6Objective 1

Integrating LLMs with Offensive Operations GCIH Practice Questions (Page 6)

Part of the Emerging Technologies and Offensive Operations domain, which makes up ~5% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~5–8 in this domain), expect 5–8 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
7concepts

Questions 26–30

  1. 26application · medium

    A security team is reviewing their email gateway's ability to detect AI-generated phishing emails. They want to implement a control that specifically targets the use of LLMs to create evasive content. Which control is most effective?

    Select an answer first
  2. 27application · medium

    A red team is using an LLM to generate a variety of phishing emails for a simulated attack. The team wants to test the effectiveness of different email templates. Which approach is most efficient?

    Select an answer first
  3. 28expert · hard

    During an incident response, a defender discovers a set of fake social media accounts that are posting technical details about the attack. The details are partially correct but contain deliberate inaccuracies. The defender suspects the attacker is using an LLM to generate this disinformation. What is the best way to confirm this?

    Select an answer first
  4. 29expert · hard

    A penetration tester is using an LLM to generate a malicious macro for a Word document. The tester needs the macro to evade antivirus and also be functional. The tester has limited time and must choose between two approaches: (1) use the LLM to generate a unique obfuscated macro, or (2) use the LLM to modify a known macro. Which approach is more likely to succeed?

    Select an answer first
  5. 30foundation · easy

    How can an LLM be used to create evasive techniques that bypass security controls?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.