GCIH Practice Question: Detecting Exploitation and Covert Communication Tools
An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?
⚠ Common exam trap
Candidates frequently misidentify the event as a simple brute force attack, missing the critical transition from authentication failures to immediate post-exploitation commands, which characterizes a successful account takeover.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Credential stuffing followed by automated reconnaissance.
This sequence is a classic indicator of credential stuffing or password spraying followed by immediate reconnaissance. The shift from multiple failures (guessing) to a successful login (success) and then immediate discovery commands (post-exploitation) strongly suggests a compromised account being used by an adversary. This pattern is vital to detect early in the kill chain before the attacker moves laterally or achieves persistence within the network environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A user struggling to remember their password.
Why it's wrong here
While a user might fail a login, the subsequent execution of reconnaissance commands like 'whoami' and 'net user' is not typical user behavior. These commands are diagnostic tools used by attackers to map the environment after gaining access. Ignoring this activity would result in missing an active security breach.
- ✓
Credential stuffing followed by automated reconnaissance.
Why this is correct
The combination of multiple failed logins and immediate post-exploitation commands is a high-confidence indicator of account compromise. The attacker is mapping the environment to plan further movement. Detecting this progression allows the responder to isolate the compromised account before the adversary can escalate privileges or deploy additional malicious tools.
- ✗
A network administrator performing routine maintenance.
Why it's wrong here
Administrative maintenance does not typically involve repeated failed logins followed by 'whoami' checks. Even if an administrator forgot a password, they would not need to run enumeration commands immediately upon login. This behavior deviates significantly from standard administrative workflows and should be treated as a high-priority security incident.
- ✗
An automated script updating software versions.
Why it's wrong here
Software update scripts are pre-configured and do not usually fail logins due to incorrect passwords. Furthermore, they perform specific tasks rather than running reconnaissance commands like 'net user'. This scenario does not align with the behavior of legitimate administrative automation tools and strongly points to malicious activity.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.