GCIH Malware and AI-Assisted Investigations Practice Question
An analyst uses an AI assistant to summarize a malware report and generate response steps. Before executing any recommended commands on production systems, what is the most important action?
⚠ Common exam trap
The trap here is trusting AI-generated commands as authoritative and executing them on production systems without independent verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the commands against authoritative documentation and test them in a non-production environment.
AI-generated response steps must be treated as suggestions, not instructions. Verifying commands against authoritative documentation and testing them in a non-production environment prevents accidental outages and data loss. This practice preserves production stability and evidence integrity while still allowing the analyst to benefit from AI-assisted summarization and drafting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ask the AI to confirm that its own recommendations are correct.
Why it's wrong here
Self-confirmation by the same AI model does not provide independent validation and can reinforce errors. Language models may restate incorrect commands with confidence. Trustworthy verification requires an external source such as vendor documentation, a second analyst, or a controlled test. Relying on the model to check itself defeats the purpose of validation.
- ✗
Execute the commands immediately to contain the threat before it spreads.
Why it's wrong here
Speed does not justify running unverified commands on production systems. An incorrect command could delete critical files, break services, or erase evidence needed for the investigation. Containment should use known-good procedures, and any AI-recommended steps must be validated first. Urgency is addressed by having pre-approved playbooks, not by skipping verification.
- ✗
Save the AI output as the official incident record without modification.
Why it's wrong here
AI output may contain inaccuracies, unsupported claims, or hallucinated details, so it should not be treated as the authoritative record. Incident documentation must reflect verified facts and analyst decisions. The AI summary can be a starting draft, but it requires review, correction, and supplementation with evidence before being filed as the official record.
- ✓
Verify the commands against authoritative documentation and test them in a non-production environment.
Why this is correct
AI assistants can produce plausible but incorrect commands or outdated syntax. Verifying against authoritative vendor documentation and testing in a lab or non-production system prevents accidental disruption of production services. This validation step is essential before executing any AI-recommended action, especially commands that modify system state or delete data.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.