Courseiva

GCIH Integrating LLMs with Offensive Operations Practice Question

An incident responder is using an LLM to automate the parsing of obfuscated PowerShell scripts found during a breach. What is the primary operational risk when feeding these scripts into a cloud-based LLM API?

⚠ Common exam trap

Candidates often focus on the efficiency of the AI tool, failing to consider the severe privacy and security risks of uploading potentially sensitive, proprietary, or breach-related data to a public cloud-based LLM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The input data may be retained and used for future model training, potentially leaking incident indicators.

Sharing obfuscated code with cloud-based LLMs risks leaking proprietary infrastructure details or sensitive credentials embedded within scripts into the vendor's training corpus. This data exposure violates confidentiality policies and undermines incident containment efforts. Security professionals must utilize local models or sanitized code snippets to prevent inadvertent data exfiltration while leveraging AI-assisted analysis for complex malware triage during active incident response workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The LLM will automatically execute the PowerShell commands in the cloud environment.

    Why it's wrong here

    Cloud-based LLMs act as text processing engines and do not possess native execution environments for arbitrary scripts. The primary danger lies in the ingestion of potentially sensitive data into the model’s context window, rather than unauthorized execution of the provided code within the vendor's infrastructure.

  • ✗

    The LLM will refuse to analyze the script because it contains malicious syntax.

    Why it's wrong here

    Most modern LLMs are trained to analyze code regardless of intent, provided they do not violate specific safety policies regarding generating malicious payloads. Analysts often use LLMs to deobfuscate malicious scripts; the refusal to process is unlikely unless the content triggers severe safety guardrails.

  • ✓

    The input data may be retained and used for future model training, potentially leaking incident indicators.

    Why this is correct

    Cloud providers often ingest user input for continuous model improvement. If sensitive environment variables, internal server names, or specific attack indicators are present in the script, they could be reflected in future model outputs, resulting in a significant data leakage incident that compromises the organization's security posture.

  • ✗

    The LLM will inject backdoors into the code during the deobfuscation process.

    Why it's wrong here

    While LLMs can exhibit hallucinations or introduce logic errors, the active injection of backdoors during a simple analysis task is not the primary risk. The threat is primarily related to data leakage rather than the model actively weaponizing code during the analysis phase of an investigation.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.