20+ practice questions focused on Endpoint Attack and Pivoting — one of the most tested topics on the GIAC Certified Incident Handler exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Endpoint Attack and Pivoting PracticeAn attacker has compromised a Windows workstation and successfully injected a beacon into a legitimate process. They wish to perform lateral movement using Mimikatz to extract credentials from LSASS. Which technique minimizes the likelihood of triggering endpoint detection for credential dumping?
Explanation: Extracting credentials directly from the Local Security Authority Subsystem Service (LSASS) memory is a high-fidelity alert for modern EDR solutions. Utilizing a memory-safe approach like leveraging existing cached tokens or performing a minidump via a less suspicious tool helps evade heuristic detection. Incident responders monitor LSASS access patterns closely, so minimizing interaction with this process is crucial for maintaining stealth while performing post-exploitation activities within a compromised network environment.
An attacker is pivoting through a network using SSH dynamic port forwarding. Which TWO actions should an incident responder perform to identify and disrupt this tunnel?
Explanation: Identifying SSH tunneling requires analyzing network flow data for persistent, low-bandwidth connections originating from an internal host to an external IP, often over non-standard ports or SSH defaults. Disrupting these tunnels necessitates both blocking the external destination at the firewall and killing the specific process on the infected endpoint to prevent persistence. Understanding the mechanics of SSH dynamic forwarding is essential for incident handlers to effectively neutralize active pivot points.
Which THREE of the following are common indicators of 'living off the land' (LotL) techniques used during pivoting?
Explanation: Living off the land techniques involve using built-in system tools like PowerShell, WMI, and BITS to execute attacks. Because these tools are trusted and signed by the vendor, they bypass traditional signature-based defenses. Incident responders must focus on behavioral analysis, command-line auditing, and script block logging to detect these activities, as the presence of the binary itself is not an indicator of compromise.
Refer to the exhibit. Which security control is most effective at preventing this specific pivot-related activity?
Explanation: The command shows the use of PowerShell to download a file from an internal or external source. Implementing Constrained Language Mode (CLM) and restricting PowerShell's ability to initiate network connections through AppLocker or Windows Defender Application Control (WDAC) are critical. Furthermore, network segmentation prevents compromised endpoints from reaching unauthorized internal servers, limiting the attacker's ability to stage tools during the pivoting phase of an attack.
During lateral movement, an attacker attempts to clear their tracks. Which TWO actions would effectively prevent the incident responder from identifying the source of the compromise?
Explanation: Attackers prioritize log clearing and artifact removal to slow down incident response. Clearing Windows Event Logs (e.g., Security, System) destroys critical evidence of authentication and process creation. Deleting temporary files and prefetch artifacts makes it difficult for responders to perform timeline analysis, which is essential for determining the initial entry point and the extent of lateral movement across the network.
+15 more Endpoint Attack and Pivoting questions available
Practice all Endpoint Attack and Pivoting questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Endpoint Attack and Pivoting. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Endpoint Attack and Pivoting questions on the GCIH frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Endpoint Attack and Pivoting is tested as part of the GIAC Certified Incident Handler blueprint. Practicing with targeted Endpoint Attack and Pivoting questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GCIH practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Endpoint Attack and Pivoting is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Endpoint Attack and Pivoting practice session with instant scoring and detailed explanations.
Start Endpoint Attack and Pivoting Practice →