GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
An incident responder is investigating a suspected credential dumping incident on a Windows Server 2019 host. The attacker is believed to have used a tool that reads the Local Security Authority Subsystem Service (LSASS) process memory. Which two indicators, when observed together, most strongly suggest that LSASS memory was accessed for credential theft? (Choose two.)
⚠ Common exam trap
The trap here is treating log clearing or network logon events as primary indicators of credential dumping, when the definitive evidence is the specific handle access rights and process creation command lines targeting LSASS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event ID 4656 with handle access rights including 0x1010 or 0x1410 requested against the lsass.exe process object
The two strongest indicators of LSASS memory access for credential theft are Event ID 4656 showing handle access rights of 0x1010 or 0x1410 against lsass.exe, and Event ID 4688 showing process creation with command-line arguments referencing lsass and dump operations. Together they confirm both the access request and the tool used, providing high-fidelity evidence of credential dumping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event ID 1102 indicating the security audit log was cleared
Why it's wrong here
Event ID 1102 indicates the audit log was cleared, which is a defense evasion technique often performed after credential theft. However, it is not a direct indicator of LSASS memory access. While it may appear in a credential dumping scenario, it does not specifically confirm that LSASS was accessed and is therefore not the strongest paired indicator.
- ✓
Event ID 4656 with handle access rights including 0x1010 or 0x1410 requested against the lsass.exe process object
Why this is correct
Event ID 4656 with handle rights 0x1010 (PROCESS_QUERY_INFORMATION | PROCESS_VM_READ) or 0x1410 indicates a process opened lsass.exe with the permissions needed to read its memory. This is a strong indicator of credential dumping tools like Mimikatz or ProcDump, which must obtain these specific access rights to extract credentials from LSASS.
- ✗
Event ID 5145 showing access to the \\*\IPC$ share from a remote IP address
Why it's wrong here
Event ID 5145 logs detailed file share access, and IPC$ access is routine for remote management and SMB operations. It does not indicate LSASS memory access on the local host. While IPC$ access can be part of lateral movement, it is not a specific indicator of credential dumping from LSASS memory and would not corroborate the handle access events.
- ✗
Event ID 4624 logon type 3 from the local host to itself using a machine account
Why it's wrong here
Logon type 3 (network) from a machine account to itself is common in normal service operations and does not indicate LSASS access. Credential dumping involves reading process memory, not authenticating over the network. This event would not correlate with the handle access or process creation artifacts that characterize LSASS memory theft.
- ✓
Event ID 4688 showing a process created with a command line containing 'lsass' and 'dump' or 'MiniDump'
Why this is correct
Event ID 4688 with process creation auditing enabled captures command lines. Tools like ProcDump or comsvcs.dll MiniDump use explicit command-line arguments referencing lsass and dump operations. This, combined with handle access events, provides corroborating evidence that a process was created specifically to dump LSASS memory for credential extraction.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.