Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?

⚠ Common exam trap

The trap here is assuming that traffic on port 443 is always TLS; attackers frequently use common ports with custom protocols to bypass security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A covert channel using a non-standard protocol over a common port

The correct answer is a covert channel using a non-standard protocol over a common port. Attackers often use ports like 443 to blend in with normal traffic, but they may implement their own protocol instead of TLS to avoid detection or because it's simpler. The persistent, scheduled connection suggests a beaconing implant that checks in with a C2 server. This technique can evade firewalls that allow outbound 443 traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A misconfigured application using the wrong port

    Why it's wrong here

    While misconfigurations happen, the combination of a custom protocol, persistent connection, and scheduled timing strongly suggests deliberate covert communication. A misconfiguration would likely be more sporadic and not consistently occur at the same time each night. The fixed header also indicates a designed protocol, not an accident.

  • ✗

    A legitimate software update service

    Why it's wrong here

    Legitimate software updates typically use standard protocols like HTTPS (TLS) or HTTP. The use of a custom protocol on port 443 is highly suspicious. Additionally, the scheduled 2 AM connection could be a scheduled task, but the non-standard protocol indicates malicious intent rather than legitimate update traffic.

  • ✗

    A denial-of-service attack

    Why it's wrong here

    A DoS attack would typically involve a high volume of traffic to overwhelm a target, not a persistent, low-volume connection with a custom protocol. The scenario describes a single workstation communicating with an external IP, which is more indicative of command and control than a DoS attack.

  • ✓

    A covert channel using a non-standard protocol over a common port

    Why this is correct

    The traffic uses port 443, which is typically associated with HTTPS, but the payload is not TLS. Instead, it uses a custom protocol. This is a classic covert channel technique: hiding malicious communication on a commonly allowed port to bypass firewalls and evade detection. The persistent, scheduled nature also suggests a beaconing implant.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.