
GIAC Certified Incident Handler
Domain 1Objective 2
Network and Log Investigations GCIH Practice Questions (Page 8)
Part of the Incident Response and Investigation domain, which makes up ~20% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 6–11 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 36–40
- 36
In a pcap, you see a TCP handshake to port 445, followed by an SMB negotiation, then a large data transfer from the client to the server. The client IP is a known compromised workstation. What is the most likely activity?
Select an answer first - 37
During an investigation, you open a pcap file and notice a series of TCP SYN packets sent to consecutive ports on a single host, each followed by an RST/ACK response. The source IP is consistent, and the packets span a few seconds. Which conclusion is best supported by this traffic pattern?
Select an answer first - 38
You are analyzing a pcap that contains encrypted TLS traffic to a known malicious IP. You suspect data exfiltration but cannot decrypt the traffic. Which approach is most likely to provide useful evidence?
Select an answer first - 39
During an incident, you need to collect a firewall log file from a Linux server for later analysis. What is the most appropriate method to preserve the evidence's integrity?
Select an answer first - 40
A pcap shows a series of TCP connections from an internal host to an external IP on port 53, but the packets are not standard DNS queries. The payloads are binary and the connections are short-lived. You suspect DNS tunneling. Which additional evidence would most strongly confirm this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.