Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 1Objective 3

Malware and AI Assisted Investigations GCIH Practice Questions (Page 4)

Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts

Questions 16–20

  1. 16application · medium

    A company's SOC uses an AI-based email gateway that flags phishing emails with a confidence score. During a simulated phishing test, the gateway flagged a legitimate internal email as 'phishing' with a high confidence score. What is the best way to handle this situation?

    Select an answer first
  2. 17foundation · easy

    What is the primary benefit of combining AI-driven insights with manual analysis in malware investigations?

    Select an answer first
  3. 18application · medium

    An analyst is investigating a suspicious PowerShell script that evaded traditional antivirus. The analyst uses an AI-based tool that flags the script as malicious based on obfuscation patterns. To confirm the finding, the analyst decides to manually review the script. Which manual review step is most effective?

    Select an answer first
  4. 19application · medium

    A security operations center (SOC) receives an alert from an AI-based endpoint detection tool about a PowerShell script that exhibits obfuscated code and attempts to download a file from a rarely visited domain. The AI model flagged it as 'high confidence malware'. The analyst needs to validate the alert before escalating. Which action best combines AI insights with traditional analysis?

    Select an answer first
  5. 20application · medium

    An analyst is investigating a file that an AI tool flagged as malware. The analyst's manual static analysis shows the file is a legitimate installer from a known vendor. What should the analyst do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.