Reinforce GCIH concepts with active-recall study cards covering all 15 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For GCIH preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the GCIH question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your GCIH flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real GCIH exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass GCIH.
Sample cards from the GCIH flashcard bank. Read the question, think of the answer, then read the explanation below.
An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?
Implement IAM roles that grant temporary security credentials via STS.
Utilizing IAM roles with temporary security credentials is the best practice for cloud security. By assuming roles, you eliminate the risks associated with static access keys, which are frequently leaked or stolen. This approach aligns with the principle of least privilege, as temporary tokens expire automatically, reducing the window of opportunity for an attacker to exploit compromised credentials, thereby enhancing the overall security posture of the cloud environment.
Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?
The command syntax is incorrect for creating a service.
The 'sc query' command is used to inspect existing services, not to register new ones. The attacker attempted to use the query syntax rather than the 'create' command to define the service. Understanding the proper syntax for service manipulation is critical for incident handlers to identify how attackers attempt to achieve persistence via Windows Service Control Manager or other system-level configuration methods.
An incident handler observes that an internal server is leaking sensitive file system structure via SMB. Which configuration change most effectively prevents SMB null session enumeration?
Set RestrictAnonymous to 2
Disabling anonymous access and restricting null sessions is critical for hardening SMB. By configuring the RestrictAnonymous registry key to 2, the operating system denies all anonymous users from enumerating shares, usernames, and groups. This prevents attackers from performing reconnaissance against the server, significantly reducing the attack surface by ensuring that only authenticated users can query sensitive SMB metadata during the initial stages of a lateral movement attempt.
Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is the most appropriate next step for an incident handler?
Examine process memory and network artifacts to confirm malicious injection.
The exhibit shows a clear anomaly where a parent-child relationship (PowerShell spawning svchost) is highly suspicious, especially when associated with an external connection. While the AI score is high, it is a heuristic indicator. The handler must verify this via manual inspection of the process memory and network artifacts to confirm if this is a legitimate system injection or a malicious beacon, ensuring that response actions are based on verified facts.
An incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?
Precomputed rainbow table attacks
MD5 is cryptographically broken and prone to collision attacks. Without a salt, identical passwords generate identical hashes, enabling precomputed rainbow table attacks. This allows attackers to instantly crack most of the database by comparing hashes against known lists. Incident responders must prioritize salting and moving to modern algorithms like Argon2 or bcrypt to ensure that stolen credentials cannot be easily reversed, protecting users from credential stuffing attacks elsewhere.
An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?
Enable PowerShell Script Block Logging to capture de-obfuscated code.
Static signatures fail against randomized Base64 encoding. Behavioral detection, specifically script block logging, captures the de-obfuscated code before execution. This is essential for incident handlers because attackers frequently use obfuscation to bypass simple keyword filters. Script block logging provides the exact command executed in memory, allowing for accurate analysis of the intent regardless of the obfuscation technique employed by the attacker.
An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?
Monitor process lineage for common utilities launching suspicious child processes.
Detecting LotLbins requires focusing on process lineage and behavioral context rather than just the binary name. By correlating parent-child process relationships—specifically looking for common utilities like certutil.exe or mshta.exe spawning suspicious network connections or child shells—defenders can distinguish malicious intent from standard management tasks. This approach is critical in modern environments where native tools are frequently abused to bypass static signature-based detection mechanisms used by legacy EDR solutions.
An incident responder is evaluating a compromised web application server where attackers utilized a custom Large Language Model framework to dynamically generate targeted SQL injection payloads based on real-time database error feedback. Which architectural vulnerability in the LLM integration enabled this adaptive offensive capability?
Unrestricted execution loops connecting model output directly to database querying modules
Integrating LLMs directly into closed-loop feedback mechanisms without rigorous output filtering allows agents to parse error logs and iteratively refine exploitation strings. Incident handlers must inspect agent memory state and prompt chains to determine how dynamic payload generation bypassed static signature-based Web Application Firewalls.
An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?
netstat -ano
Identifying the link between network sockets and the system process is critical during incident handling. Netstat or ss utilities, specifically when used with process identification flags, allow responders to map external traffic to local binaries. This visibility is essential for distinguishing between legitimate service communication and unauthorized exfiltration or command-and-control beacons, enabling the responder to terminate malicious processes and isolate affected infrastructure quickly.
An attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?
Path Traversal
This scenario describes a Path Traversal attack, where an application fails to validate user input used to construct file system paths. By using dot-dot-slash notation, the attacker escapes the intended directory to access unauthorized files. This represents a critical failure in input validation and access control, commonly leading to full system compromise or sensitive data exposure, necessitating robust file path normalization and strictly defined allow-lists.
An incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?
Broken Object Level Authorization
This scenario clearly demonstrates Broken Object Level Authorization, where authorization validation is missing in the object identifier tier. Attackers exploit this design flaw to harvest unauthorized records horizontally or vertically. Incident handlers must recognize API1:2023 risks during web application forensics to properly scope data exfiltration incidents and remediate flawed access control logic across microservices.
An incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?
Error-based SQL injection via unescaped search input processed directly by the database engine
Error-based SQL injection occurs when database error messages are displayed directly to the end user through the web interface. Attackers leverage these verbose debugging messages to extract database schemas, table names, and sensitive column contents piece by piece. Remediating this requires implementing custom error handling and parameterized queries globally.
Refer to the exhibit. An analyst identifies these entries on a critical server. What should the analyst conclude regarding the process associated with PID 4?
The process is a legitimate Windows kernel operation for SMB file sharing.
In Windows environments, PID 4 is reserved for the System process. In the context of port 445 (SMB), this is standard behavior for the Server service and kernel-level file sharing. Recognizing legitimate OS behavior is critical to avoid false positives. If the source IPs were unknown or the connection volume was anomalous, further investigation into kernel-mode drivers or rootkits would be required, but this output represents standard file sharing functionality.
Refer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?
NTLM; risk of credential theft and lateral movement
The exhibit identifies the use of mode 1000, which corresponds to NTLM hashes. The command uses attack mode 0 (straight dictionary attack). This combination is highly effective against Windows networks where NTLM is utilized. The risk is that if the NTLM hash is cracked, the attacker gains the user's secret, allowing for lateral movement or privilege escalation across the entire Windows domain environment using pass-the-hash or direct authentication.
Which Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?
-O
The -O flag instructs Nmap to perform TCP/IP stack fingerprinting, which analyzes specific behaviors of the target's networking stack. This is vital for responders to classify assets, identify potential legacy systems, and determine if the target matches known vulnerable OS versions during the scoping phase of an incident investigation or routine security audit.
The GCIH flashcard bank covers all 15 official blueprint domains published by GIAC. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Securing Credentials and Data in Cloud
Endpoint Attack and Pivoting
SMB Security
Malware and AI-Assisted Investigations
Understanding Passwords
Detecting Exploitation and Covert Communication Tools
Detecting Evasive and Post-Exploitation Techniques
Integrating LLMs with Offensive Operations
Network and Log Investigations
Exploiting Insecure Web App References
Web App API Attacks
Web App Injection Attacks
Incident Response and Cyber Investigation
Attacking Passwords
Scanning and Mapping
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that GCIH questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.GCIH questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective GCIH study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free GCIH flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 322+ original GCIH flashcards across all 15 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official GIAC exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official GCIH exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included