Courseiva

GCIH · domain

Detecting Evasive and Post-Exploitation Techniques

This GCIH domain covers how attackers evade detection and operate after initial compromise on Windows and Linux hosts. Questions present exhibits, logs, or process trees and ask you to identify the technique, explain why a control failed, or choose a detection strategy that catches the activity without flooding analysts with benign administrative noise.

26 questions4 easy13 medium9 hard

Focused practice

Practice Detecting Evasive and Post-Exploitation Techniques questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Detecting Evasive and Post-Exploitation Techniques

You must identify evasive and post-exploitation techniques from exhibits, process trees, and logs, then pick detections that catch them with low false positives. The critical skill is correlating parent-child process lineage and command-line arguments rather than trusting binary names or signatures alone.

Recognizing process injection and hollowing via Sysmon Event ID 8 and memory anomalies

Detecting living-off-the-land binaries such as PowerShell, certutil, and rundll32 abused for execution

Identifying Linux persistence through /etc/ld.so.preload and malicious shared object libraries

Explaining why application whitelisting, AV, or policy controls fail against evasive techniques

Watch out for

Common Detecting Evasive and Post-Exploitation Techniques exam traps

  • ▸Assuming a signed Microsoft binary like rundll32 or certutil is safe because of its signature, missing that attackers abuse trusted binaries to blend in.
  • ▸Treating every PowerShell execution as malicious, ignoring script block logging, parent process lineage, and command-line context that separate admin scripts from attacker tradecraft.
  • ▸Confusing process injection with process hollowing, or missing that security tools monitoring only the primary process fail to see injected code in a legitimate host process.

Question index

All Detecting Evasive and Post-Exploitation Techniques questions (26)

Click any question to see the full explanation, or start a practice session above.

1

Which technique describes an attacker using a legitimate process to hide malicious code, commonly used to bypass security products that monitor only the primary process?

Medium
2

An incident responder is examining a Windows Server 2016 system that is suspected of being compromised. The responder runs 'net user' and sees a new account named 'Support' that was not there before. The account is a member of the local Administrators group. The responder checks the Security event log and sees Event ID 4720 (A user account was created) followed by Event ID 4732 (A member was added to a security-enabled local group). The responder also notices that the account has never been logged into. Which post-exploitation technique does this represent?

Medium
3

What is the primary indicator of a 'Skeleton Key' attack in an Active Directory environment?

Medium
4

A threat hunter observes outbound DNS queries from an internal workstation to a domain that resolves to an IP address owned by a cloud provider. The queries contain long, random-looking subdomains such as 'a1b2c3d4e5f6g7h8.example.com'. The volume of queries is high and consistent, occurring every few seconds. Which post-exploitation technique is most likely in use?

Medium
5

During an incident response engagement, an analyst is reviewing Windows security event logs from a domain controller. The analyst observes a series of Event ID 4769 (A Kerberos service ticket was requested) entries with encryption type 0x17 (RC4-HMAC) for multiple service accounts, originating from a single workstation within a short time frame. Which of the following best describes the attacker's activity and the appropriate detection focus?

Hard
6

A threat hunter is reviewing Sysmon logs from a Windows workstation that is suspected of being compromised. The hunter sees a process named 'svchost.exe' with a parent process of 'services.exe', but its image path is 'C:\Users\Public\svchost.exe' and it has an active network connection to an external IP address on port 443. Which two indicators should the hunter flag as highly suspicious in this scenario? (Choose two.)

Hard
7

An incident responder is analyzing a compromised Windows host and discovers that the attacker used the built-in 'sc.exe' utility to create a new service named 'WinDefendHelper' with a binary path pointing to a file in C:\Users\Public\Documents. The service was set to start automatically and the attacker then deleted the original dropper executable. Which persistence mechanism has the attacker implemented, and what is the most reliable detection artifact?

Hard
8

An incident responder is investigating a suspected credential dumping incident on a Windows Server 2019 host. The attacker is believed to have used a tool that reads the Local Security Authority Subsystem Service (LSASS) process memory. Which two indicators, when observed together, most strongly suggest that LSASS memory was accessed for credential theft? (Choose two.)

Hard
9

What is the primary purpose of 'Time Stomping' during a post-exploitation phase?

Easy
10

An incident responder notices that a local user account is performing Kerberoasting. Which event log ID should the responder examine to verify this activity?

Hard
11

Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?

Medium
12

An incident responder is analyzing a suspected process injection on a Windows host. Which two artifacts most reliably indicate that a remote thread was injected into a legitimate process? (Choose two.)

Medium
13

During an incident response engagement, you review Windows Security event logs and observe a series of 4624 logons with Logon Type 3 originating from a single workstation. The account name is the computer account of a server, and the source workstation is a user's desktop that normally never authenticates to the target server. Which post-exploitation technique is most consistent with this pattern?

Medium
14

Which of the following is a reliable method to detect an adversary using 'WMI Event Subscription' for persistence?

Medium
15

Which of the following is a sign of 'Domain Fronting' in network traffic logs?

Medium
16

During an incident response engagement, an analyst observes that a Windows workstation is making DNS queries for a domain that resolves to an IP address owned by a cloud provider. The queries are for subdomains that appear randomly generated and change frequently. The workstation also has periodic HTTPS connections to that IP. The analyst suspects domain fronting. Which of the following best describes how domain fronting is used in this scenario?

Hard
17

A SOC analyst notices that a scheduled task on a workstation was created shortly after a user opened a malicious email attachment. The task runs a PowerShell command that downloads a file from an external IP every hour. The task is configured to run under the SYSTEM account and has no associated user logon. Which post-exploitation technique does this represent?

Easy
18

An incident responder is reviewing a compromised Linux host and notices that the attacker modified the /etc/ld.so.preload file to include a path to a shared object file. Shortly after, the responder observes that common commands like 'ls' and 'ps' are returning incomplete or manipulated output. Which post-exploitation technique has the attacker most likely employed?

Easy
19

Refer to the exhibit. An attacker bypasses this policy. Why did this control fail?

Medium
20

An attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?

Medium
21

An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this activity is occurring?

Hard
22

An analyst is investigating a suspected compromise on a Windows 10 endpoint. Network telemetry shows periodic outbound HTTPS traffic to a domain that resolves to a legitimate cloud CDN IP, but the SNI in the TLS ClientHello does not match the destination domain. The endpoint has no browser activity at those times. Which technique best explains this traffic pattern?

Hard
23

An incident responder is analyzing a compromised Linux server. The responder notices that the file /etc/ld.so.preload contains the path /lib/libprocess.so, which is not a standard library. The responder suspects an attacker is using this for persistence and privilege escalation. Which post-exploitation technique is being employed?

Medium
24

A security analyst is reviewing logs from a Linux web server and notices that the 'last' command output shows a login by user 'root' from an IP address that is not part of the company's network. The login occurred at 03:00 AM, and the analyst also finds that the file /root/.ssh/authorized_keys was modified at the same time. Which post-exploitation technique has the attacker most likely used?

Easy
25

Which technique involves an attacker injecting code into a legitimate, running process to perform malicious activity while avoiding the detection of file-based scanning?

Hard
26

An incident responder investigates a Windows endpoint and discovers an unexpected service running with administrative privileges, executing a binary from an anomalous temporary directory. Reviewing the registry, the responder notices that the service binary path uses a space-separated executable path without surrounding double quotes, and the folder name contains a space. Which post-exploitation persistence and privilege escalation technique has the attacker deployed?

Medium

Frequently asked questions

What does the Detecting Evasive and Post-Exploitation Techniques domain cover on the GCIH exam?
You must identify evasive and post-exploitation techniques from exhibits, process trees, and logs, then pick detections that catch them with low false positives. The critical skill is correlating parent-child process lineage and command-line arguments rather than trusting binary names or signatures alone.
How many questions are in this domain?
This page lists all 26 Detecting Evasive and Post-Exploitation Techniques questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Detecting Evasive and Post-Exploitation Techniques questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH detecting evasive and post exploitation techniques Practice Questions