GCIH Malware and AI-Assisted Investigations Practice Question
An AI-assisted investigation tool summarizes a week of EDR telemetry and reports that a workstation 'likely performed credential dumping.' The summary cites no specific process, command line, or timestamp. What should the incident handler do first?
⚠ Common exam trap
The trap here is treating an AI summary as a confirmed finding and acting on containment or escalation without validating the underlying telemetry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Query the underlying EDR data for LSASS access events and suspicious process lineage to validate the AI claim.
AI-generated summaries are inferences that must be validated against source telemetry before action. The handler should query EDR for LSASS access, known credential dumping tool indicators, and suspicious process ancestry to confirm or refute the claim. This produces concrete evidence for escalation and avoids both unnecessary containment and missed detection. Validation is the foundational step in any AI-assisted investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate to management and legal teams because credential dumping implies a reportable breach.
Why it's wrong here
Escalating to management and legal before validating the AI summary can cause unnecessary alarm and resource expenditure. Notification obligations depend on confirmed unauthorized access to sensitive data, which has not been established. The handler's first duty is to verify the technical claim using raw telemetry, then escalate through proper channels only after evidence confirms a real incident.
- ✗
Retrain or tune the AI model because its summary lacks supporting detail.
Why it's wrong here
The absence of cited artifacts in a summary is a usability issue, not necessarily a model accuracy problem. Retraining or tuning is a long-term engineering task and does not help resolve the current potential incident. The immediate priority is to validate the claim against source data. Model improvement can be raised later through proper feedback channels after the incident is handled.
- ✓
Query the underlying EDR data for LSASS access events and suspicious process lineage to validate the AI claim.
Why this is correct
The AI summary is an unverified inference, so the handler must pivot to the raw EDR telemetry that the model used. Searching for LSASS handle requests, known dumping tools like Mimikatz or ProcDump, and unusual parent-child process relationships provides concrete evidence. This validation step confirms or refutes the claim and produces the specific artifacts needed for escalation and containment decisions.
- ✗
Isolate the workstation immediately to prevent lateral movement.
Why it's wrong here
Isolating based on an unsupported AI summary can disrupt a user and halt business processes without verified cause. While containment is important once credential dumping is confirmed, the summary lacks the specific artifacts, process names, and timestamps needed to justify such an action. The handler should first validate the claim against raw telemetry before taking containment steps.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.