GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?
⚠ Common exam trap
The trap here is assuming that traffic on port 443 is always TLS; attackers frequently use common ports with custom protocols to bypass security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A covert channel using a non-standard protocol over a common port
The correct answer is a covert channel using a non-standard protocol over a common port. Attackers often use ports like 443 to blend in with normal traffic, but they may implement their own protocol instead of TLS to avoid detection or because it's simpler. The persistent, scheduled connection suggests a beaconing implant that checks in with a C2 server. This technique can evade firewalls that allow outbound 443 traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A misconfigured application using the wrong port
Why it's wrong here
While misconfigurations happen, the combination of a custom protocol, persistent connection, and scheduled timing strongly suggests deliberate covert communication. A misconfiguration would likely be more sporadic and not consistently occur at the same time each night. The fixed header also indicates a designed protocol, not an accident.
- ✗
A legitimate software update service
Why it's wrong here
Legitimate software updates typically use standard protocols like HTTPS (TLS) or HTTP. The use of a custom protocol on port 443 is highly suspicious. Additionally, the scheduled 2 AM connection could be a scheduled task, but the non-standard protocol indicates malicious intent rather than legitimate update traffic.
- ✗
A denial-of-service attack
Why it's wrong here
A DoS attack would typically involve a high volume of traffic to overwhelm a target, not a persistent, low-volume connection with a custom protocol. The scenario describes a single workstation communicating with an external IP, which is more indicative of command and control than a DoS attack.
- ✓
A covert channel using a non-standard protocol over a common port
Why this is correct
The traffic uses port 443, which is typically associated with HTTPS, but the payload is not TLS. Instead, it uses a custom protocol. This is a classic covert channel technique: hiding malicious communication on a commonly allowed port to bypass firewalls and evade detection. The persistent, scheduled nature also suggests a beaconing implant.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.