
GIAC Certified Incident Handler
Domain 1Objective 3
Malware and AI Assisted Investigations GCIH Practice Questions (Page 2)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 6–10
- 6
In incident response, how can AI be used to enhance the triage process?
Select an answer first - 7
Which static analysis method extracts readable text from a binary to identify URLs, IP addresses, or command-line arguments embedded in the malware?
Select an answer first - 8
During an incident, an analyst discovers a file that appears to be a legitimate PDF but contains embedded JavaScript that executes when opened. The file also has a high entropy section. Which type of malware behavior is most likely indicated?
Select an answer first - 9
An analyst is examining a suspicious binary that is packed. The analyst wants to perform static analysis. What is the most important first step?
Select an answer first - 10
A security team is evaluating an AI-based malware detection tool. The tool uses machine learning to classify files as malicious or benign. During a test, the tool misclassifies a benign file as malicious. What is the most likely cause of this false positive?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.