GCIH › Endpoint Attack and Pivoting
This domain covers how attackers move from a compromised endpoint to other systems, and the artifacts they leave behind. You must recognize malicious DLL persistence, token manipulation, WMI remote execution, and PsExec lateral movement. Questions present investigation scenarios and ask you to identify the technique, its purpose, or the evidence it creates on Windows systems.
GCIH Endpoint Attack and Pivoting — All 30 Questions
Every question in this domain with answers and detailed explanations.
Securing Credentials and Data in Cloud
SMB Security
Malware and AI-Assisted Investigations
Understanding Passwords
Detecting Exploitation and Covert Communication Tools
Detecting Evasive and Post-Exploitation Techniques
Integrating LLMs with Offensive Operations
Network and Log Investigations
Exploiting Insecure Web App References
Web App API Attacks
Web App Injection Attacks
Incident Response and Cyber Investigation
Attacking Passwords
Scanning and Mapping