Courseiva

GCIH Integrating LLMs with Offensive Operations Practice Question

A penetration testing team is integrating a locally hosted LLM into its post-exploitation tooling to help draft PowerShell and Bash commands from natural-language objectives. Before deployment, the team lead must identify controls that limit the blast radius if the model is manipulated through crafted input. (Choose two.)

⚠ Common exam trap

The trap here is treating output-quality improvements such as fine-tuning or interpretability logging as security controls, when blast-radius reduction actually requires isolation and human approval before execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execute all model-generated commands inside a disposable, network-isolated sandbox until they are reviewed and approved.

Limiting blast radius requires containment and human control over what actually executes. Running generated commands in a disposable, network-isolated sandbox ensures any manipulated output is harmless, and requiring explicit human approval before execution against targets prevents harmful commands from ever running. Attention-weight logging offers no containment, standing admin credentials amplify impact, and fine-tuning improves quality without creating any security boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fine-tune the model on the team's historical engagement reports to improve command accuracy and reduce manipulation risk.

    Why it's wrong here

    Fine-tuning can improve stylistic and contextual accuracy, but it does not create a security boundary and may even increase susceptibility if the training data contains sensitive or attacker-influenced content. It provides no containment when a crafted prompt induces harmful output, so blast radius remains unbounded. Because the objective is to limit impact rather than improve output quality, this option does not address the requirement and is not one of the two correct controls.

  • ✓

    Execute all model-generated commands inside a disposable, network-isolated sandbox until they are reviewed and approved.

    Why this is correct

    Running generated commands in a disposable, isolated sandbox contains any destructive or unintended action the model produces, including commands induced by crafted input. Because the environment is ephemeral and lacks network reach into production or client systems, manipulation cannot translate into real-world impact. Review and approval before promotion to live systems adds a human gate, directly limiting blast radius as required by the scenario.

  • ✓

    Require human review and explicit approval of each generated command before it is executed against any target.

    Why this is correct

    A mandatory human approval gate ensures no model output reaches a target without an operator assessing its intent and safety. If crafted input causes the model to propose destructive or out-of-scope commands, the reviewer intercepts them before execution, directly limiting blast radius. This control complements sandboxing by adding judgment that automated filtering may miss, and it is a recognized practice when integrating generative tools into offensive workflows.

  • ✗

    Enable verbose logging of the model's internal attention weights so operators can detect manipulated prompts.

    Why it's wrong here

    Attention weights are low-level numerical artifacts that are not interpretable as a reliable signal of prompt manipulation, and reviewing them does not constrain what the generated commands can do. This control consumes significant effort while providing no containment if a malicious instruction succeeds. It fails to limit blast radius because it neither isolates execution nor restricts the model's ability to influence live systems, so it does not satisfy the requirement.

  • ✗

    Grant the LLM service account standing administrative credentials on the engagement jump host to avoid execution failures.

    Why it's wrong here

    Standing administrative credentials dramatically expand the impact of any successful manipulation, because generated commands inherit that privilege. This is the opposite of limiting blast radius; it turns a contained mistake into a potential full compromise of the jump host and connected targets. Least privilege and ephemeral, task-scoped credentials are appropriate here, making this option definitively wrong for the stated objective.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.