GCIH Malware and AI-Assisted Investigations Practice Question
A GCIH incident handler is investigating a Linux server that an AI-based anomaly detector flagged for unusual outbound traffic. The handler suspects the server is beaconing to a C2 server but the traffic is encrypted and the beacon interval appears randomized. The handler has a packet capture and wants to apply a technique that can identify the beaconing pattern despite the randomization. Which approach should the handler use?
⚠ Common exam trap
The trap here is assuming that encrypted C2 cannot be analyzed, when timing metadata like inter-arrival intervals remains visible and is often sufficient to detect beaconing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform frequency analysis on the inter-arrival times of outbound connections to the suspected destination.
When beacon intervals are randomized, the payload is encrypted, and signatures are unavailable, timing metadata becomes the most reliable signal. Frequency analysis on inter-arrival times can expose an underlying periodic component or a base interval with jitter, which is characteristic of beaconing. Certificate inspection and signature matching depend on known-bad artifacts, and TLS decryption is impractical without keys, so timing analysis is the correct approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perform frequency analysis on the inter-arrival times of outbound connections to the suspected destination.
Why this is correct
Beaconing, even with randomized intervals, often retains a statistical signature such as a base interval with jitter or a periodic component. Frequency analysis on inter-arrival times can reveal that underlying periodicity, distinguishing C2 traffic from routine user-driven connections. This technique works on encrypted traffic because it analyzes timing metadata rather than payload, directly addressing the randomized beacon interval challenge.
- ✗
Decrypt the TLS session using the server's private key and search the payload for known C2 strings.
Why it's wrong here
Decrypting TLS requires the server's private key, which the handler does not possess, or a session key captured via a key log file that is unlikely to exist on a compromised production server. Even if decryption were possible, the scenario emphasizes randomized beacon intervals, which is a timing problem, not a payload-content problem. This approach is impractical and misaligned with the actual investigative need.
- ✗
Run a signature-based IDS rule set updated with the latest C2 domain blocklist against the packet capture.
Why it's wrong here
Signature and blocklist matching only works when the C2 domain or payload pattern is already known and present in the rule set. The scenario describes encrypted traffic to a suspected C2 with randomized intervals, which is precisely the case where signature matching fails. This approach cannot reveal the beaconing pattern and may produce false negatives, so it does not meet the handler's requirement.
- ✗
Inspect the TLS certificate presented by the suspected C2 server for a self-signed or mismatched common name.
Why it's wrong here
Certificate inspection can reveal poor operational security, such as self-signed certificates or names that do not match the domain, but modern C2 frameworks often use valid certificates from legitimate CAs. Furthermore, many beaconing channels are not TLS at all, and the certificate check does not address the randomized interval. This approach may yield a useful indicator but does not reliably identify the beaconing pattern described.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.