GCIH Network and Log Investigations Practice Question
An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?
⚠ Common exam trap
Candidates often select packet capture tools or general bandwidth monitors, forgetting that mapping specific ports directly to local process IDs requires endpoint socket utilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
netstat -ano
Identifying the link between network sockets and the system process is critical during incident handling. Netstat or ss utilities, specifically when used with process identification flags, allow responders to map external traffic to local binaries. This visibility is essential for distinguishing between legitimate service communication and unauthorized exfiltration or command-and-control beacons, enabling the responder to terminate malicious processes and isolate affected infrastructure quickly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tcpdump -i eth0
Why it's wrong here
Tcpdump captures raw packets traversing a network interface. While it reveals the content and destination of the traffic, it does not inherently link packets to a specific process ID or the binary running on the local host, making it less direct for identifying the culprit process.
- ✓
netstat -ano
Why this is correct
The -ano flags in netstat display all active connections, include numeric addresses, and show the process ID owning each connection. This direct mapping allows the responder to identify the exact binary or service responsible for the outbound port 443 traffic, facilitating immediate containment actions against the process.
- ✗
nmap -sV target
Why it's wrong here
Nmap is a network discovery and security auditing tool used for port scanning and service version detection. It is designed for reconnaissance rather than local system process introspection. Using it against the local machine would only confirm open ports, not the process owner responsible for existing connections.
- ✗
ifconfig -a
Why it's wrong here
Ifconfig is a legacy utility used for viewing and configuring network interfaces. It provides information about IP addresses, netmasks, and hardware status but lacks any capability to display active TCP/UDP connections or map those connections to specific processes running within the host operating system.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.