Courseiva

GCIH Malware and AI-Assisted Investigations Practice Question

An analyst notices that an AI-powered detection tool is flagging legitimate administrative PowerShell scripts as malicious. Which approach should the analyst take to improve model precision?

⚠ Common exam trap

Candidates frequently suggest adjusting global thresholds or rewriting the entire detection engine, missing the direct solution of retraining the model with specific false-positive samples.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the training set to include these scripts as 'benign' examples.

Model precision is improved by incorporating false positives into the training loop. By labeling these administrative scripts correctly, the analyst provides the model with the necessary 'negative' examples to learn the nuances between legitimate management tasks and malicious activity. This reduces future noise, allowing the incident response team to focus on actual threats rather than spending time triaging recurring, known-good administrative actions that currently trigger alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the detection rule entirely until the AI update is released.

    Why it's wrong here

    Disabling the rule creates a blind spot. If an attacker mimics administrative behavior, the team will have no visibility into the activity. The correct approach is to refine the detection logic or adjust the threshold rather than completely removing the security control, which leaves the environment vulnerable to living-off-the-land techniques.

  • ✓

    Update the training set to include these scripts as 'benign' examples.

    Why this is correct

    Adding false positives to the training set allows the model to learn the boundary between legitimate admin activity and malicious PowerShell usage. This process of continuous learning improves model accuracy over time, significantly reducing the burden on the SOC by filtering out expected, non-malicious behavior from the daily alert queue.

  • ✗

    Increase the sensitivity threshold of the AI model to ignore all PowerShell activity.

    Why it's wrong here

    Increasing the sensitivity threshold globally will lead to missing true malicious activity. PowerShell is a common vector for attack, and ignoring it is unacceptable. The refinement must be surgical, focusing on distinguishing between specific admin scripts and malicious payloads, rather than applying a blunt, system-wide suppression of all PowerShell-related alerts.

  • ✗

    Replace the AI model with a static signature-based detection system.

    Why it's wrong here

    Static signatures are ineffective against modern, obfuscated, or living-off-the-land malware. Replacing a dynamic, AI-based system with a brittle, static one will result in a net loss of detection capability. The goal is to improve the existing model's performance, not to regress to older technologies that are easily bypassed by modern threats.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.