Courseiva

GCIH Practice Question: Detecting Exploitation and Covert Communication Tools

An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?

⚠ Common exam trap

Candidates often misidentify jitter as network congestion or packet loss, failing to realize it is a deliberate, calculated technique used by C2 frameworks to mask automated communication patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Command and control beaconing with evasion techniques.

Jitter is the deliberate randomization of time intervals between network beacons to evade detection by algorithms looking for fixed-cadence heartbeats. By introducing this variability, attackers make their C2 traffic appear more 'human' or natural. Recognizing this technique is vital for incident handlers because it highlights the sophistication of the C2 infrastructure, requiring advanced statistical analysis beyond simple threshold-based alerts to identify the underlying automated pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data exfiltration using high-speed burst transfers.

    Why it's wrong here

    High-speed burst transfers are used for moving large volumes of data quickly, which does not involve jitter. Jitter is a characteristic of command-and-control heartbeats, not bulk data exfiltration. Misidentifying the traffic type can lead the analyst to ignore the persistent, low-and-slow nature of the attacker's primary communication channel.

  • ✓

    Command and control beaconing with evasion techniques.

    Why this is correct

    Jitter is a common C2 evasion technique used to defeat detection systems that look for perfectly periodic connections. By adding randomness to the delay between beacons, the adversary masks the automated nature of the communication. This indicates a high level of sophistication and necessitates heuristic-based detection methodologies.

  • ✗

    Standard web browsing activity during lunch hours.

    Why it's wrong here

    Standard web browsing does not exhibit consistent, jitter-adjusted beaconing. While human behavior is irregular, it does not follow the mathematical patterns of jittered automated C2. Attributing this to user behavior ignores the technological indicators of a persistent threat that is specifically designed to blend into standard network traffic.

  • ✗

    Network congestion caused by heavy application traffic.

    Why it's wrong here

    Network congestion causes packet loss and delayed arrival times, but it is a byproduct of infrastructure load, not a security technique. Jitter in the context of a C2 beacon is an intentional configuration, whereas congestion is a random network state. Analysts must distinguish between infrastructure issues and security threats.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.