Courseiva

GCIH Integrating LLMs with Offensive Operations Practice Question

An incident response team wants its LLM assistant to triage endpoint telemetry and recommend containment actions, but leadership is concerned that a manipulated model could recommend disabling critical production services. Which design choice best mitigates that concern?

⚠ Common exam trap

The trap here is accepting logging, tagging, or fine-tuning as safeguards when the model still retains the authority to execute containment actions directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the model to output recommendations only, with all containment actions requiring explicit analyst authorization through the existing ticketing workflow.

The strongest mitigation is to keep the model in an advisory role, where every containment action requires explicit analyst authorization through an established workflow. This removes the model's ability to disable production services regardless of manipulation, and the ticketing process preserves human judgment and accountability. Direct execution with tag limits, post-hoc logging, or fine-tuning all leave an execution path or rely on controls that cannot guarantee protection of critical services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the model to output recommendations only, with all containment actions requiring explicit analyst authorization through the existing ticketing workflow.

    Why this is correct

    Restricting the model to advisory output means no containment action occurs without an analyst deliberately authorizing it, so a manipulated recommendation cannot disable production services on its own. Routing approvals through the existing ticketing workflow preserves accountability and gives responders context to judge each suggestion. This design directly addresses leadership's concern by ensuring the model never holds execution authority over critical systems.

  • ✗

    Grant the model direct containment authority but require it to log every action to the SIEM after execution.

    Why it's wrong here

    Post-execution logging creates an audit record but does not prevent the harmful action from occurring; production services would already be disabled by the time anyone reviews the log. Detection after the fact is not mitigation of the risk leadership raised. Because containment impact is immediate and potentially severe, this option leaves the core concern unaddressed and is therefore incorrect for the scenario.

  • ✗

    Fine-tune the model on historical containment decisions so it learns to avoid disabling services that are critical.

    Why it's wrong here

    Fine-tuning shapes typical behavior but offers no guarantee against adversarial manipulation, and the model may still recommend disabling a critical service when prompted with crafted telemetry. It also provides no execution barrier, so any failure of the tuning translates directly into production impact. Since leadership wants assurance that critical services cannot be disabled by the model, this approach does not deliver the required control.

  • ✗

    Allow the model to invoke containment APIs directly but limit it to disabling services that are not tagged as critical.

    Why it's wrong here

    Direct API invocation gives the model execution authority, and tag-based restrictions depend on accurate, current asset tagging that is frequently incomplete or stale. A manipulated model could target a mislabeled service or chain actions that affect critical dependencies. Because the concern is that the model could disable critical production services, retaining any direct execution path fails to provide the assurance leadership is seeking.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.