
GIAC Certified Incident Handler
Domain 1Objective 2
Network and Log Investigations GCIH Practice Questions (Page 4)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 16–20
- 16
A firewall log shows a large volume of outbound DNS queries from an internal server to a single external IP, with each query using a unique subdomain such as 'abc123.malicious-domain.com'. The server is not a DNS resolver. What does this pattern most likely indicate?
Select an answer first - 17
You are building a timeline of an incident. The pcap shows an ARP scan at 10:00:00, followed by an SMB connection to a file server at 10:05:00, and then an HTTP POST to an external site at 10:10:00. What is the most likely sequence of attacker actions?
Select an answer first - 18
Which section is typically included in an incident report to provide a high-level overview for management?
Select an answer first - 19
An incident responder is collecting log files from a compromised server as evidence. Which action is most important to maintain the integrity of the evidence?
Select an answer first - 20
An analyst is correlating authentication logs from a domain controller and a VPN gateway. The VPN log shows a successful login from a remote IP at 02:00, and the domain controller log shows a successful login for the same user from the same IP at 02:05. What does this correlation indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.