GCIH Integrating LLMs with Offensive Operations Practice Question
An incident handler is documenting an intrusion in which the attacker used a locally hosted LLM to summarize harvested credentials and prioritize lateral movement targets. The handler wants to cite the model's activity in the report but must avoid presenting model output as established fact. Which approach best meets that requirement?
⚠ Common exam trap
The trap here is equating recovered model output with the attacker's confirmed reasoning, when the model may have hallucinated and the handler did not observe the attacker acting on it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reproduce the attacker's prompts against the same model build and label the resulting summaries as analytical reconstructions rather than confirmed attacker statements.
When attacker tooling includes an LLM, the handler's job is to distinguish observed artifacts from reconstructed inference. Re-running the same prompts on the same model build and labeling the output as a reconstruction preserves analytical insight while avoiding the claim that model output equals attacker intent. Verbatim attribution, omission, and false attribution all distort the record in different ways.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Omit the LLM activity entirely because model output cannot be treated as reliable evidence in an incident report.
Why it's wrong here
Omitting the activity removes context that explains how the attacker prioritized targets and moved laterally. Incident reports are expected to document attacker tooling, including AI assistance, with appropriate caveats. Excluding it entirely leaves the timeline incomplete and could cause the client to miss a capability they need to defend against in the future.
- ✓
Reproduce the attacker's prompts against the same model build and label the resulting summaries as analytical reconstructions rather than confirmed attacker statements.
Why this is correct
Re-running the same prompts on the same model build lets the handler show what the attacker likely saw while clearly labeling it as a reconstruction. This distinguishes inference from evidence and avoids asserting that unrecovered model output was fact. It preserves analytical value in the report without overstating certainty, which is the standard the scenario demands.
- ✗
Attribute the summaries to the incident handler's own analysis so the report reads as a single consistent narrative.
Why it's wrong here
Presenting machine-generated content as the handler's independent analysis misrepresents the investigative process and hides the role of the attacker's tooling. It also obscures chain-of-custody concerns, since a reader cannot tell what was observed versus inferred. The report loses both transparency and the ability to trace how conclusions were reached.
- ✗
Present the model's summaries verbatim as the attacker's own conclusions, since the model output was recovered from the host.
Why it's wrong here
Even output recovered from disk reflects what the model produced at that moment, which may include hallucinated or incomplete content. Presenting it as the attacker's confirmed reasoning conflates machine generation with human intent and can mislead readers. It also ignores that prompts and model versions may have changed between runs, undermining the accuracy the report requires.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.