GCIH › Detecting Exploitation and Covert Communication Tools
This GCIH domain covers recognizing attacker tradecraft on hosts and networks: suspicious process lineage, covert channels tunneled through ICMP, DNS, or HTTP, and the command-line evidence left behind. Questions present real command output, packet captures, or process listings and ask you to identify attacker intent, the tool in use, or the correct investigative step.
GCIH Detecting Exploitation and Covert Communication Tools — All 28 Questions
Every question in this domain with answers and detailed explanations.
Securing Credentials and Data in Cloud
Endpoint Attack and Pivoting
SMB Security
Malware and AI-Assisted Investigations
Understanding Passwords
Detecting Evasive and Post-Exploitation Techniques
Integrating LLMs with Offensive Operations
Network and Log Investigations
Exploiting Insecure Web App References
Web App API Attacks
Web App Injection Attacks
Incident Response and Cyber Investigation
Attacking Passwords
Scanning and Mapping