GCIH · domain
Detecting Exploitation and Covert Communication Tools
This GCIH domain covers recognizing attacker tradecraft on hosts and networks: suspicious process lineage, covert channels tunneled through ICMP, DNS, or HTTP, and the command-line evidence left behind. Questions present real command output, packet captures, or process listings and ask you to identify attacker intent, the tool in use, or the correct investigative step.
Focused practice
Practice Detecting Exploitation and Covert Communication Tools questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Detecting Exploitation and Covert Communication Tools
Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.
Correlating Parent Process ID with execution path to spot process masquerading or injection
Using tcpdump, Wireshark, netstat, ss, and lsof to expose covert channels
Reading Linux command output to infer attacker intent such as persistence or exfiltration
Watch out for
Common Detecting Exploitation and Covert Communication Tools exam traps
- ▸Judging a process malicious by name alone instead of validating PPID, path, and parent-child lineage
- ▸Assuming ICMP is benign and skipping payload inspection of echo request and reply data
- ▸Confusing legitimate administrative tooling with attacker tradecraft without checking timing, volume, or destination
Question index
All Detecting Exploitation and Covert Communication Tools questions (14)
Click any question to see the full explanation, or start a practice session above.
An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?
Medium2Which THREE actions are effective at identifying hidden 'living-off-the-land' (LotL) binary usage in a compromised system?
Hard3When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?
Hard4Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?
Medium5During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?
Medium6During incident response, you observe that a compromised host is sending ICMP echo request packets with a payload size of 1000 bytes to an external IP. The payload appears to contain non-printable characters. What is the most likely explanation?
Medium7During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?
Medium8An analyst discovers a malicious DLL file in a system directory. What is the most effective way to identify which process loaded this DLL into memory?
Medium9An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?
Medium10A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?
Easy11An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?
Medium12During an incident response engagement, an analyst reviews network flow records and notices a compromised Linux server making outbound connections to an external host. Each connection lasts exactly 45 seconds, transfers roughly 2 KB, and then terminates; a new connection begins 15 seconds later. The destination IP changes every few hours among a pool of addresses in the same /24. The payload is fully encrypted and no standard application protocol headers are visible. Which technique is the attacker MOST likely using to maintain command-and-control while evading detection?
Hard13During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP sockets. Which network analysis method provides the most reliable detection mechanism for this specific covert channel regardless of packet payload obfuscation?
Medium14An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?
MediumOther domains
All GCIH exam domains
Frequently asked questions
- What does the Detecting Exploitation and Covert Communication Tools domain cover on the GCIH exam?
- Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.
- How many questions are in this domain?
- This page lists all 14 Detecting Exploitation and Covert Communication Tools questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Detecting Exploitation and Covert Communication Tools questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.