GCIH › Network and Log Investigations
This GCIH domain covers evidence gathering and analysis across network captures and host/security logs. You must map activity to Windows Event IDs, interpret NetFlow and packet captures, and recognize tunneling or credential-theft patterns. Questions present short scenarios and ask which artifacts or indicators confirm the activity, so you need to know what each data source actually reveals.
GCIH Network and Log Investigations — All 32 Questions
Every question in this domain with answers and detailed explanations.
Securing Credentials and Data in Cloud
Endpoint Attack and Pivoting
SMB Security
Malware and AI-Assisted Investigations
Understanding Passwords
Detecting Exploitation and Covert Communication Tools
Detecting Evasive and Post-Exploitation Techniques
Integrating LLMs with Offensive Operations
Exploiting Insecure Web App References
Web App API Attacks
Web App Injection Attacks
Incident Response and Cyber Investigation
Attacking Passwords
Scanning and Mapping