GCIH • Practice Exam 2 — 20 Questions
Free GCIH practice exam 2 — 20 questions with explanations. No signup required.
During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.