Be able to pick the right artifact for a scenario: Event IDs for credential attacks, flow data for traffic patterns, packet captures for protocol detail, and DNS logs for tunneling. The key skill is correlating multiple sources rather than trusting a single indicator.
Start practicing
Network and Log Investigations — choose a session length
Free · No account required
Domain overview
This GCIH domain covers evidence gathering and analysis across network captures and host/security logs. You must map activity to Windows Event IDs, interpret NetFlow and packet captures, and recognize tunneling or credential-theft patterns. Questions present short scenarios and ask which artifacts or indicators confirm the activity, so you need to know what each data source actually reveals.
Exam objectives
Windows Security Event IDs for NTLM logon and explicit credential use, including 4624 logon types
NetFlow and flow records for identifying command-and-control, exfiltration volume, and lateral movement
Wireshark and tcpdump packet analysis of TLS handshakes, application payloads, and beaconing intervals
DNS query logs and packet inspection for tunneling indicators such as long labels and high query volume
Confusing Event ID 4624 logon types, especially Type 3 network versus Type 10 RemoteInteractive, when tracing Pass-the-Hash activity.
Assuming encrypted TLS traffic hides everything, ignoring metadata like certificate fields, JA3, SNI, and packet sizes and timing.
Treating any large DNS query as tunneling, missing that volume, entropy, and TXT or NULL record abuse matter more.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?
2An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?
3Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?
4You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?
5An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?
6Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?
7You are investigating an alert regarding a 'Beaconing' pattern. Which aspect of the network connection is most indicative of automated C2 communication versus human browsing activity?
8During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?
9An incident responder notices an unusual outbound connection from a workstation to an external IP address on TCP port 443. Packet capture analysis shows that the SSL/TLS handshake completes, but the subsequent application-layer data payload is fully encrypted and does not match standard HTTPS browser traffic patterns. Which log investigation method provides the most reliable approach to determine if this traffic represents malicious command and control activity?
10An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect the use of stolen NTLM credential material for lateral movement? (Choose TWO)
11An incident handler is examining a packet capture from a compromised workstation and observes a series of DNS queries for domains like 'a1b2c3d4e5.exfil.example.com', each followed by a large TXT response. The queries are sent at regular 30-second intervals, and the subdomains contain random-looking alphanumeric strings. Which of the following techniques is MOST likely being used by the attacker?
12An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?
13A security analyst is reviewing a packet capture from a compromised host and observes a series of DNS queries for randomly generated subdomains of a single domain, each followed by a TXT record response containing encoded data. The queries occur at regular intervals of approximately 60 seconds. Which type of attack is most strongly indicated by this pattern?
14An incident responder is analyzing a network capture to identify potential command-and-control (C2) communication. The capture shows a workstation making regular DNS queries to 'update.microsoft.com' every 60 seconds, each followed by a small HTTPS session to a different IP address. The HTTPS sessions use self-signed certificates and the User-Agent string is 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'. Which TWO of the following indicators most strongly suggest malicious C2 activity? (Choose two.)
15An incident handler is examining a web server's access logs after a suspected SQL injection attempt. The log shows a request with a long URL containing multiple single quotes and 'UNION SELECT' statements. Which log field is most critical to correlate this request with other events to determine if the attack succeeded?
16During a network investigation, an incident responder notices a high volume of outbound DNS queries to a single external domain, with each query containing a long, random-looking subdomain. The queries occur at regular intervals of approximately 30 seconds. Which type of attack is most likely indicated?
17An incident handler is investigating a suspected compromised Windows workstation. They review Windows Security event logs and notice a large number of Event ID 4625 (An account failed to log on) followed by a single Event ID 4624 (An account was successfully logged on) from the same source IP within a short period. Which of the following best describes the activity?
18An incident handler is analyzing a packet capture to identify command-and-control (C2) communication. Which two characteristics are most indicative of C2 traffic? (Choose two.)
19An incident handler is analyzing a packet capture and notices a high volume of TCP SYN packets sent to multiple ports on a single target host, with no corresponding SYN-ACK responses. The source IP is spoofed. What type of activity does this indicate?
20An incident handler is analyzing a PCAP and observes a series of TCP packets with the SYN flag set, followed by a single RST/ACK packet from the destination. What is the most likely explanation for this pattern?
21An incident handler is triaging a suspected beaconing implant on a Windows workstation. NetFlow records show a repeating outbound connection to the same external IP address every 60 seconds, but the packets are only 200 bytes each, so no payload is captured. The handler wants to confirm the beacon's timing jitter and any command-and-control content without deploying a new agent to the endpoint. Which investigative approach BEST accomplishes this?
Be able to pick the right artifact for a scenario: Event IDs for credential attacks, flow data for traffic patterns, packet captures for protocol detail, and DNS logs for tunneling. The key skill is correlating multiple sources rather than trusting a single indicator.
The Courseiva GCIH question bank contains 21 questions in the Network and Log Investigations domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network and Log Investigations domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included