GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?
⚠ Common exam trap
Candidates often suggest blacklisting specific binary names, which is ineffective against LotLbins because legitimate administrative tools will always be present in a production environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Monitor process lineage for common utilities launching suspicious child processes.
Detecting LotLbins requires focusing on process lineage and behavioral context rather than just the binary name. By correlating parent-child process relationships—specifically looking for common utilities like certutil.exe or mshta.exe spawning suspicious network connections or child shells—defenders can distinguish malicious intent from standard management tasks. This approach is critical in modern environments where native tools are frequently abused to bypass static signature-based detection mechanisms used by legacy EDR solutions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all PowerShell execution via Group Policy Objects.
Why it's wrong here
Blocking PowerShell entirely is impractical in modern Windows environments as it is essential for system administration and maintenance. Disabling it breaks core enterprise functionality, disrupts legitimate automation workflows, and does not stop attackers from utilizing other scripting languages like VBScript or JScript for payload delivery and execution.
- ✗
Flag any process execution involving native Windows binaries.
Why it's wrong here
Alerting on any native Windows binary execution will generate an extreme volume of false positives. Legitimate services, background tasks, and user-initiated operations rely on these binaries thousands of times daily. This strategy lacks the necessary granularity to filter out standard noise and would likely cause severe alert fatigue for analysts.
- ✓
Monitor process lineage for common utilities launching suspicious child processes.
Why this is correct
Analyzing parent-child relationships allows security teams to identify anomalies such as a web server process spawning cmd.exe or a utility like certutil.exe initiating an outbound connection. This behavioral pattern is a hallmark of post-exploitation activity, providing high-fidelity signals that distinguish administrative use cases from malicious abuse of trusted binaries.
- ✗
Implement static file hash signatures for all known LotLbins.
Why it's wrong here
Static hash signatures are easily circumvented by attackers through minor binary renaming or the use of genuine, signed binaries that are already present on the system. Because these utilities are legitimate OS components, their hashes do not change, making signature-based detection completely ineffective against living-off-the-land techniques used by modern adversaries.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.