GCIH Malware and AI-Assisted Investigations Practice Question
An attacker has compromised a host and established persistence using a malicious scheduled task that executes an encoded PowerShell command. The command downloads a second-stage payload from a legitimate cloud storage service. Your AI-assisted EDR has flagged the activity but provided only a low-confidence alert. As the incident responder, you need to determine the next investigative step. Which of the following actions is MOST likely to yield actionable intelligence about the second-stage payload?
⚠ Common exam trap
The trap here is focusing on containment or scanning without first extracting and analyzing the payload, which is essential for understanding the threat and preventing recurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decode the PowerShell command and extract the URL to retrieve the payload for analysis.
Decoding the PowerShell command and retrieving the payload is the most direct way to gain intelligence. It allows you to analyze the malware, extract IOCs, and understand the attack chain. Other options either destroy evidence, are unlikely to detect the payload, or provide limited context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately isolate the host and rebuild it from a known-good image.
Why it's wrong here
Isolating and rebuilding is a containment step, but it may destroy evidence and does not provide intelligence about the second-stage payload. In incident response, understanding the attacker's tools and techniques is crucial for scoping the incident and preventing further compromise. Rebuilding without analysis could leave other systems vulnerable.
- ✓
Decode the PowerShell command and extract the URL to retrieve the payload for analysis.
Why this is correct
Decoding the PowerShell command reveals the exact URL used to download the second-stage payload. Retrieving and analyzing that payload in a sandbox will provide details about its capabilities, C2 infrastructure, and potential indicators. This directly advances the investigation by obtaining the actual malware for further study, rather than relying on low-confidence alerts.
- ✗
Review the scheduled task's XML definition to identify the author and creation time.
Why it's wrong here
While the task's metadata can provide some context, it rarely yields actionable intelligence about the payload itself. Attackers often use compromised credentials or system accounts, and timestamps can be manipulated. This step is less valuable than directly obtaining and analyzing the payload.
- ✗
Run a full antivirus scan on the host to detect and remove the second-stage payload.
Why it's wrong here
Antivirus may not detect a custom or obfuscated payload, and running a scan could alert the attacker. Moreover, this does not provide actionable intelligence about the payload's functionality or C2. The goal is to analyze, not just remove, to understand the threat and improve defenses.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.