
GIAC Certified Incident Handler
Domain 1Objective 3
Malware and AI Assisted Investigations GCIH Practice Questions (Page 10)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 46–49
- 46
An incident response team is investigating a file that an AI-based classifier labels as 'likely malware' with 90% confidence. Static analysis shows the file is a signed executable from a reputable vendor, but it also contains a suspicious DLL that is not signed. The team must decide whether to block the file across the enterprise. The file is used by a critical business application. What is the best course of action?
Select an answer first - 47
During incident response, an analyst observes a file that, when executed, encrypts user documents and displays a ransom note demanding payment in cryptocurrency. Which type of malware is this an example of?
Select an answer first - 48
An analyst needs to safely execute a malware sample to observe its behavior. The sample is known to potentially spread via network shares. Which environment setup is most appropriate for dynamic analysis?
Select an answer first - 49
A company is implementing an AI-based incident response system that can automatically contain threats. The system uses a machine learning model to decide whether to isolate a host. The model was trained on historical data from the company's environment. During a real incident, the model fails to isolate a host that later spreads malware. What is the most likely reason for this failure?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.