GCIH › Incident Response and Cyber Investigation
This GCIH domain covers the incident response lifecycle, forensic artifact collection, and adversary tradecraft analysis. Questions present scenarios requiring you to identify attacker techniques like living-off-the-land, select the right evidence sources, and apply preparation-phase controls. Expect exhibit-based items referencing process trees, Sysmon-style telemetry, and web server logs.
GCIH Incident Response and Cyber Investigation — All 27 Questions
Every question in this domain with answers and detailed explanations.
Securing Credentials and Data in Cloud
Endpoint Attack and Pivoting
SMB Security
Malware and AI-Assisted Investigations
Understanding Passwords
Detecting Exploitation and Covert Communication Tools
Detecting Evasive and Post-Exploitation Techniques
Integrating LLMs with Offensive Operations
Network and Log Investigations
Exploiting Insecure Web App References
Web App API Attacks
Web App Injection Attacks
Attacking Passwords
Scanning and Mapping