GCIH Incident Response and Cyber Investigation Practice Question
An incident responder is reviewing an IDS alert and needs to determine whether a suspicious executable that ran on a Windows workstation has been seen in other attacks. Which framework should the responder consult to map the observed adversary behavior to known tactics, techniques, and procedures?
⚠ Common exam trap
Many candidates confuse a lifecycle or analytical model with a technique knowledge base, since all four frameworks are commonly referenced in incident response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MITRE ATT&CK
MITRE ATT&CK is designed specifically to catalog adversary tactics, techniques, and procedures from real-world observations. Mapping the suspicious executable to ATT&CK techniques allows the responder to understand what the binary is doing in terms of known behaviors and which threat actors employ those methods. This supports faster triage, prioritization, and detection engineering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NIST SP 800-61
Why it's wrong here
NIST SP 800-61 is a guide for incident handling lifecycle phases such as preparation, detection, containment, eradication, and recovery. It does not catalog adversary tactics and techniques. The responder needs TTP mapping, not process guidance. While useful for structuring the response, it will not identify which techniques the executable represents or which actors use them.
- ✗
The Diamond Model of Intrusion Analysis
Why it's wrong here
The Diamond Model relates adversary, capability, infrastructure, and victim in a single event. It is useful for pivot analysis and campaign tracking but does not enumerate techniques or provide mappings to threat groups. The responder seeking to identify known TTPs from a binary's behavior needs a technique catalog, which the Diamond Model does not supply.
- ✓
MITRE ATT&CK
Why this is correct
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It lets the responder map the executable's behavior to specific techniques, understand which threat groups use them, and prioritize detection and response actions. This directly answers the need to contextualize the suspicious binary against known TTPs.
- ✗
The Cyber Kill Chain
Why it's wrong here
The Cyber Kill Chain describes seven stages of an intrusion, from reconnaissance through actions on objectives. It helps explain where an attack is in its lifecycle but does not provide a granular, searchable matrix of techniques. The responder needs technique-level detail, which the Kill Chain does not offer. It is a model, not a TTP database.
About these practice questions
This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.