GCIH Malware and AI-Assisted Investigations Practice Question
A junior incident handler is reviewing an alert from an AI-powered email security gateway that flagged a message as a likely AI-generated phishing attempt. The gateway's model outputs a confidence score but no explanation. The handler wants to gather corroborating evidence from the message headers and body to support the classification before escalating. Which artifact would best help the handler verify that the message was generated or augmented by an AI tool?
⚠ Common exam trap
The trap here is conflating phishing indicators like SPF failures or reply-to mismatches with evidence of AI authorship, when those address origin and spoofing instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The message body's writing style and any embedded AI watermark or metadata.
To corroborate an AI-generation classification, the handler should look at the content itself, since AI-written text often shows distinctive stylistic uniformity and may carry watermarks or metadata. Header-based artifacts like SPF, DKIM, and Received chains address origin and authentication, not authorship. Focusing on the body's style and embedded markers directly supports or refutes the gateway's model output before escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The sender's display name and the reply-to address mismatch.
Why it's wrong here
A mismatch between the display name and the reply-to address is a classic phishing indicator and can suggest impersonation, but it does not demonstrate AI involvement in composing the message. Attackers have used mismatched reply-to addresses for decades without AI. This artifact supports a phishing determination, not the specific AI-generation hypothesis, so it is not the best choice here.
- ✗
The SPF and DKIM authentication results in the headers.
Why it's wrong here
SPF and DKIM results tell the handler whether the sending domain authorized the sending IP and whether the message was cryptographically signed and intact. These are valuable for detecting spoofing and domain impersonation, but they say nothing about whether the text was AI-generated. A properly authenticated message can still be AI-written, so these headers do not corroborate the AI-generation claim.
- ✗
The Received header chain showing the message's relay path.
Why it's wrong here
The Received chain documents the SMTP relays the message traversed and can reveal spoofing or misconfigured mail servers, which is useful for tracing origin. However, it does not indicate whether the body text was AI-generated. Many AI-generated phishing emails are sent through legitimate mail infrastructure, so the relay path alone will not corroborate the AI-generation hypothesis. It supports origin analysis but not the specific claim being validated.
- ✓
The message body's writing style and any embedded AI watermark or metadata.
Why this is correct
AI-generated text often exhibits consistent stylistic patterns, and some providers embed watermarks or metadata in generated content. Examining the body for unnatural uniformity, repeated phrasing, or embedded markers can corroborate the gateway's classification. This is the most direct artifact for validating that the content itself was AI-generated, which is exactly what the handler needs before escalating the alert.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.