You must identify evasive and post-exploitation techniques from exhibits, process trees, and logs, then pick detections that catch them with low false positives. The critical skill is correlating parent-child process lineage and command-line arguments rather than trusting binary names or signatures alone.
Start practicing
Detecting Evasive and Post-Exploitation Techniques — choose a session length
Free · No account required
Domain overview
This GCIH domain covers how attackers evade detection and operate after initial compromise on Windows and Linux hosts. Questions present exhibits, logs, or process trees and ask you to identify the technique, explain why a control failed, or choose a detection strategy that catches the activity without flooding analysts with benign administrative noise.
Exam objectives
Recognizing process injection and hollowing via Sysmon Event ID 8 and memory anomalies
Detecting living-off-the-land binaries such as PowerShell, certutil, and rundll32 abused for execution
Identifying Linux persistence through /etc/ld.so.preload and malicious shared object libraries
Explaining why application whitelisting, AV, or policy controls fail against evasive techniques
Assuming a signed Microsoft binary like rundll32 or certutil is safe because of its signature, missing that attackers abuse trusted binaries to blend in.
Treating every PowerShell execution as malicious, ignoring script block logging, parent process lineage, and command-line context that separate admin scripts from attacker tradecraft.
Confusing process injection with process hollowing, or missing that security tools monitoring only the primary process fail to see injected code in a legitimate host process.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?
2An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this activity is occurring?
3Which technique describes an attacker using a legitimate process to hide malicious code, commonly used to bypass security products that monitor only the primary process?
4An incident responder notices that a local user account is performing Kerberoasting. Which event log ID should the responder examine to verify this activity?
5What is the primary purpose of 'Time Stomping' during a post-exploitation phase?
6Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?
7Refer to the exhibit. An attacker bypasses this policy. Why did this control fail?
8Which of the following is a sign of 'Domain Fronting' in network traffic logs?
9Which technique involves an attacker injecting code into a legitimate, running process to perform malicious activity while avoiding the detection of file-based scanning?
10What is the primary indicator of a 'Skeleton Key' attack in an Active Directory environment?
11Which of the following is a reliable method to detect an adversary using 'WMI Event Subscription' for persistence?
12An incident responder investigates a Windows endpoint and discovers an unexpected service running with administrative privileges, executing a binary from an anomalous temporary directory. Reviewing the registry, the responder notices that the service binary path uses a space-separated executable path without surrounding double quotes, and the folder name contains a space. Which post-exploitation persistence and privilege escalation technique has the attacker deployed?
13During an incident response engagement, you review Windows Security event logs and observe a series of 4624 logons with Logon Type 3 originating from a single workstation. The account name is the computer account of a server, and the source workstation is a user's desktop that normally never authenticates to the target server. Which post-exploitation technique is most consistent with this pattern?
14An analyst is investigating a suspected compromise on a Windows 10 endpoint. Network telemetry shows periodic outbound HTTPS traffic to a domain that resolves to a legitimate cloud CDN IP, but the SNI in the TLS ClientHello does not match the destination domain. The endpoint has no browser activity at those times. Which technique best explains this traffic pattern?
15A SOC analyst notices that a scheduled task on a workstation was created shortly after a user opened a malicious email attachment. The task runs a PowerShell command that downloads a file from an external IP every hour. The task is configured to run under the SYSTEM account and has no associated user logon. Which post-exploitation technique does this represent?
16A threat hunter is reviewing Sysmon logs from a Windows workstation that is suspected of being compromised. The hunter sees a process named 'svchost.exe' with a parent process of 'services.exe', but its image path is 'C:\Users\Public\svchost.exe' and it has an active network connection to an external IP address on port 443. Which two indicators should the hunter flag as highly suspicious in this scenario? (Choose two.)
17An incident responder is analyzing a suspected process injection on a Windows host. Which two artifacts most reliably indicate that a remote thread was injected into a legitimate process? (Choose two.)
18An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload contains the path /lib/libprocess.so, which is not a standard library. The responder suspects an attacker is using this for persistence and privilege escalation. Which post-exploitation technique is being employed?
19During an incident response engagement, an analyst observes that a Windows workstation is making DNS queries for a domain that resolves to an IP address owned by a cloud provider. The queries are for subdomains that appear randomly generated and change frequently. The workstation also has periodic HTTPS connections to that IP. The analyst suspects domain fronting. Which of the following best describes how domain fronting is used in this scenario?
20An incident responder is examining a Windows Server 2016 system that is suspected of being compromised. The responder runs 'net user' and sees a new account named 'Support' that was not there before. The account is a member of the local Administrators group. The responder checks the Security event log and sees Event ID 4720 (A user account was created) followed by Event ID 4732 (A member was added to a security-enabled local group). The responder also notices that the account has never been logged into. Which post-exploitation technique does this represent?
21A security analyst is reviewing logs from a Linux web server and notices that the 'last' command output shows a login by user 'root' from an IP address that is not part of the company's network. The login occurred at 03:00 AM, and the analyst also finds that the file /root/.ssh/authorized_keys was modified at the same time. Which post-exploitation technique has the attacker most likely used?
22An incident responder is analyzing a compromised Windows host and discovers that the attacker used the built-in 'sc.exe' utility to create a new service named 'WinDefendHelper' with a binary path pointing to a file in C:\Users\Public\Documents. The service was set to start automatically and the attacker then deleted the original dropper executable. Which persistence mechanism has the attacker implemented, and what is the most reliable detection artifact?
23An incident responder is investigating a suspected credential dumping incident on a Windows Server 2019 host. The attacker is believed to have used a tool that reads the Local Security Authority Subsystem Service (LSASS) process memory. Which two indicators, when observed together, most strongly suggest that LSASS memory was accessed for credential theft? (Choose two.)
24A threat hunter observes outbound DNS queries from an internal workstation to a domain that resolves to an IP address owned by a cloud provider. The queries contain long, random-looking subdomains such as 'a1b2c3d4e5f6g7h8.example.com'. The volume of queries is high and consistent, occurring every few seconds. Which post-exploitation technique is most likely in use?
25An incident responder is reviewing a compromised Linux host and notices that the attacker modified the /etc/ld.so.preload file to include a path to a shared object file. Shortly after, the responder observes that common commands like 'ls' and 'ps' are returning incomplete or manipulated output. Which post-exploitation technique has the attacker most likely employed?
26During an incident response engagement, an analyst is reviewing Windows security event logs from a domain controller. The analyst observes a series of Event ID 4769 (A Kerberos service ticket was requested) entries with encryption type 0x17 (RC4-HMAC) for multiple service accounts, originating from a single workstation within a short time frame. Which of the following best describes the attacker's activity and the appropriate detection focus?
You must identify evasive and post-exploitation techniques from exhibits, process trees, and logs, then pick detections that catch them with low false positives. The critical skill is correlating parent-child process lineage and command-line arguments rather than trusting binary names or signatures alone.
The Courseiva GCIH question bank contains 26 questions in the Detecting Evasive and Post-Exploitation Techniques domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Detecting Evasive and Post-Exploitation Techniques domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included