Courseiva

GCIH Network and Log Investigations Practice Question

An incident responder notices an unusual outbound connection from a workstation to an external IP address on TCP port 443. Packet capture analysis shows that the SSL/TLS handshake completes, but the subsequent application-layer data payload is fully encrypted and does not match standard HTTPS browser traffic patterns. Which log investigation method provides the most reliable approach to determine if this traffic represents malicious command and control activity?

⚠ Common exam trap

Candidates often assume that standard TLS traffic on port 443 is inherently safe or focus heavily on external IP reputation checks, missing the fact that attackers routinely leverage standard ports for encrypted command and control channels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Correlate the network connection timestamp with endpoint process execution logs to identify the exact binary that initiated the socket.

Correlating endpoint process execution logs with network connection data via Sysmon Event ID 3 and Event ID 1 reveals the parent process responsible for establishing the socket. Relying solely on destination port 443 or external reputation feeds is insufficient because modern adversaries frequently tunnel malicious traffic over standard ports and encrypted channels to blend in with legitimate enterprise web traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a reverse DNS lookup on the destination IP address to verify if the domain belongs to a known content delivery network.

    Why it's wrong here

    Reverse DNS lookups can easily point to compromised infrastructure, legitimate cloud hosting providers, or dynamic DNS services abused by attackers. Threat actors frequently host command and control servers on reputable cloud platforms, rendering DNS ownership records unreliable for determining malicious intent.

  • ✗

    Inspect the certificate issuer authority within the TLS handshake to confirm if it matches internal corporate enterprise signing policies.

    Why it's wrong here

    Attackers can obtain valid, trusted SSL certificates for their malicious domains through automated providers like Let's Encrypt. Checking the certificate issuer alone will often show a valid, trusted CA, failing to expose the malicious nature of the application payload.

  • ✓

    Correlate the network connection timestamp with endpoint process execution logs to identify the exact binary that initiated the socket.

    Why this is correct

    Correlating network connection timestamps with endpoint process execution logs allows analysts to identify the exact binary that initiated the socket. This bridges the visibility gap between network telemetry and host activity, confirming whether an unauthorized script or tool spawned the connection.

  • ✗

    Analyze the TCP window size scaling factors during the initial three-way handshake to detect anomalies indicative of tunneling tools.

    Why it's wrong here

    TCP window size scaling factors vary widely depending on the operating system stack, network latency, and intermediate routing hardware. Relying on window size anomalies for detecting advanced tunneling tools yields an unacceptably high rate of false positives in enterprise networks.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.