Sample questions
GIAC Certified Incident Handler practice questions
An analyst uses an LLM to generate a C++ exploit. The model provides code that uses an deprecated memory copy function. What is the most appropriate action for the analyst to take?
Integrating LLMs with Offensive OperationsmediumSee the answer and why each option is right or wrong →When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?
Detecting Exploitation and Covert Communication ToolshardSee the answer and why each option is right or wrong →What is the primary risk associated with using 'aggressive' scan timing templates (like T4 or T5) in an environment with high network latency?
Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?
Which THREE of the following are essential components of an effective AI-assisted malware hunting strategy?
Refer to the exhibit. An attacker bypasses this policy. Why did this control fail?
Detecting Evasive and Post-Exploitation TechniquesmediumSee the answer and why each option is right or wrong →An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect t…
An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthor…
Refer to the exhibit. An analyst deploys this policy to detect threats. Why is the 'parent_process' condition specifically targeting 'w3wp.exe'?
Which THREE items are essential components of an API security documentation strategy for incident responders?
An incident responder analyzes a web application log and discovers that an attacker successfully extracted database schema names by manipulating a parameter where the application d…
Which TWO of the following are common indicators that a password database has been compromised?
Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?
An incident handler is analyzing a severe Cross-Site Scripting (XSS) incident where malicious JavaScript stole administrator session cookies. Which TWO of the following defensive c…
A GCIH analyst is reviewing web server logs and sees repeated requests to /search?q=... where the q parameter contains strings like ../../../etc/passwd and ....//....//etc/shadow.…
During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP so…
Detecting Exploitation and Covert Communication ToolsmediumSee the answer and why each option is right or wrong →Which technique describes an attacker using a legitimate process to hide malicious code, commonly used to bypass security products that monitor only the primary process?
Detecting Evasive and Post-Exploitation TechniquesmediumSee the answer and why each option is right or wrong →Why is it dangerous to leave port 445 open to the public internet on a Windows server?
Refer to the exhibit. What is the goal of the 'sekurlsa::logonpasswords' command in the Mimikatz tool, and why is it considered a 'game over' scenario for a compromised system?
An incident responder is investigating a Windows domain controller and discovers that an attacker has successfully dumped the NTDS.dit database. During offline analysis, the respon…
During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the paylo…
Detecting Exploitation and Covert Communication ToolsmediumSee the answer and why each option is right or wrong →An incident responder investigating a compromised Windows workstation discovers that an attacker established persistent command and control using a malicious DLL. The DLL was place…
An incident responder notices an unusual outbound connection from a workstation to an external IP address on TCP port 443. Packet capture analysis shows that the SSL/TLS handshake…
When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?