Courseiva

GCIH Integrating LLMs with Offensive Operations Practice Question

A red team operator is using a cloud-hosted LLM API to help draft PowerShell commands for a post-exploitation task. The operator wants to prevent the LLM provider from retaining the prompts for model training or later law-enforcement requests. Which configuration or contractual control should the operator verify FIRST?

⚠ Common exam trap

The trap here is assuming that encrypting the API traffic or limiting API key permissions prevents the LLM provider from retaining the prompt content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable a zero-data-retention (ZDR) setting or equivalent no-retention agreement with the LLM provider.

The operator's specific requirement is to stop the provider from retaining prompts for training or later legal requests. A zero-data-retention setting or equivalent contractual no-retention agreement is the control that directly changes provider-side storage behavior, making it the correct first check. Transport encryption, key scoping, and hashing do not alter what the provider stores after receiving the request, so they fail to satisfy the stated objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable a zero-data-retention (ZDR) setting or equivalent no-retention agreement with the LLM provider.

    Why this is correct

    A zero-data-retention setting or contractually binding no-retention agreement prevents the provider from storing prompts and completions beyond the immediate request, which directly addresses the operator's concern about later training use or legal disclosure. Without this control, other technical measures such as TLS or token scoping do not stop the provider from logging the content, so verifying retention terms first is the correct priority.

  • ✗

    Enforce TLS 1.3 with certificate pinning for all API calls to the provider.

    Why it's wrong here

    TLS 1.3 with certificate pinning protects the prompt in transit from network eavesdroppers, but it does nothing about what the provider does with the prompt after it is received. The operator's stated concern is provider-side retention and later disclosure, not interception, so transport security alone cannot satisfy the requirement and should not be the first check.

  • ✗

    Hash the PowerShell commands before sending them and ask the LLM to reconstruct them from the hashes.

    Why it's wrong here

    Hashing the commands makes them unrecoverable by the LLM, so it cannot meaningfully assist with drafting or refining the PowerShell. This defeats the purpose of integrating the LLM and is not a retention control; it simply removes the utility of the service while the provider still logs whatever was sent. It is technically unworkable for the scenario.

  • ✗

    Scope the API key to a dedicated project with minimal permissions and rotate it every 24 hours.

    Why it's wrong here

    Scoping and rotating the API key limits the blast radius if the key is stolen and reduces unauthorized use of the account, but the provider still receives and may store the prompt content under its normal terms. This control addresses credential compromise, not data retention, so it does not meet the operator's goal of preventing the provider from keeping the prompts.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.