Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

An analyst is investigating a suspected compromise on a Windows 10 endpoint. Network telemetry shows periodic outbound HTTPS traffic to a domain that resolves to a legitimate cloud CDN IP, but the SNI in the TLS ClientHello does not match the destination domain. The endpoint has no browser activity at those times. Which technique best explains this traffic pattern?

⚠ Common exam trap

The trap here is treating any traffic to a reputable CDN IP as inherently trustworthy rather than inspecting the SNI and Host header for inconsistencies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Domain fronting through a CDN to hide the true command-and-control destination

Domain fronting exploits CDN behavior where the TLS SNI and the HTTP Host header can differ, allowing traffic to appear destined for a benign domain while actually reaching attacker infrastructure. The combination of periodic non-browser HTTPS, a legitimate CDN IP, and an SNI that does not match the destination domain is characteristic. DNS tunneling, ICMP covert channels, and fast flux produce different network signatures and would not generate this specific mismatch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Domain fronting through a CDN to hide the true command-and-control destination

    Why this is correct

    Domain fronting places a benign SNI in the TLS handshake while the HTTP Host header points to the attacker's fronted domain on the same CDN. The mismatch between SNI and the actual destination, combined with non-browser beaconing, is a strong indicator. This technique abuses CDN routing to blend C2 with legitimate traffic.

  • ✗

    Fast flux DNS rotating A records to evade blocklists

    Why it's wrong here

    Fast flux rapidly changes DNS A records across many IPs, producing short TTLs and diverse resolutions. The scenario shows a stable resolution to a legitimate CDN IP with an SNI mismatch, not rotating records. Fast flux also does not explain the SNI/Host discrepancy, so it is not the best answer.

  • ✗

    DNS tunneling using TXT records to exfiltrate data

    Why it's wrong here

    DNS tunneling generates high volumes of DNS queries, often with long or encoded subdomains and TXT record responses. The observed traffic is periodic HTTPS, not DNS. While DNS tunneling can hide C2, it does not produce the SNI mismatch on TLS connections described here, so it does not fit.

  • ✗

    Beaconing over a covert channel using ICMP echo payloads

    Why it's wrong here

    ICMP-based covert channels embed data in echo request or reply payloads and would appear as ICMP traffic, not HTTPS to a CDN. The scenario explicitly describes TLS ClientHello with a mismatched SNI, which is unrelated to ICMP tunneling. Therefore ICMP covert channel is not the technique observed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.