Courseiva

GCIH · domain

Detecting Exploitation and Covert Communication Tools

This GCIH domain covers recognizing attacker tradecraft on hosts and networks: suspicious process lineage, covert channels tunneled through ICMP, DNS, or HTTP, and the command-line evidence left behind. Questions present real command output, packet captures, or process listings and ask you to identify attacker intent, the tool in use, or the correct investigative step.

14 questions1 easy10 medium3 hard

Focused practice

Practice Detecting Exploitation and Covert Communication Tools questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Detecting Exploitation and Covert Communication Tools

Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.

Correlating Parent Process ID with execution path to spot process masquerading or injection

Detecting covert C2 tunneled over ICMP echo payloads, DNS queries, or nonstandard ports

Using tcpdump, Wireshark, netstat, ss, and lsof to expose covert channels

Reading Linux command output to infer attacker intent such as persistence or exfiltration

Watch out for

Common Detecting Exploitation and Covert Communication Tools exam traps

  • ▸Judging a process malicious by name alone instead of validating PPID, path, and parent-child lineage
  • ▸Assuming ICMP is benign and skipping payload inspection of echo request and reply data
  • ▸Confusing legitimate administrative tooling with attacker tradecraft without checking timing, volume, or destination

Question index

All Detecting Exploitation and Covert Communication Tools questions (14)

Click any question to see the full explanation, or start a practice session above.

1

An incident responder reviews a packet capture from a compromised Windows workstation and notices periodic outbound DNS queries for random-looking subdomains such as 'a8f3c9e1.badguy.example'. Each query is followed by a TXT record response containing a short Base64 string. What technique is being used?

Medium
2

Which THREE actions are effective at identifying hidden 'living-off-the-land' (LotL) binary usage in a compromised system?

Hard
3

When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?

Hard
4

Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?

Medium
5

During an incident response engagement, you observe that a compromised Windows workstation periodically sends DNS queries for subdomains of 'sync.update-service.com', such as 'a1b2c3.sync.update-service.com'. The queries occur at irregular intervals, and the responses contain TXT records with long, high-entropy strings. The domain is not associated with any known legitimate service. Which technique is the adversary most likely using?

Medium
6

During incident response, you observe that a compromised host is sending ICMP echo request packets with a payload size of 1000 bytes to an external IP. The payload appears to contain non-printable characters. What is the most likely explanation?

Medium
7

During an incident response engagement on a Linux server, you discover an outbound covert channel using ICMP echo request packets that contain encoded payload data within the payload field. Which specific command-line utility should you look for in the process execution history to identify the tool responsible for generating this traffic?

Medium
8

An analyst discovers a malicious DLL file in a system directory. What is the most effective way to identify which process loaded this DLL into memory?

Medium
9

An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?

Medium
10

A security analyst notices that a user's workstation is communicating with an external IP address on port 443, but the traffic is not TLS. Instead, the packets contain a custom protocol with a fixed header. The connection is persistent and occurs every night at 2 AM. Which type of covert communication is this most likely?

Easy
11

An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?

Medium
12

During an incident response engagement, an analyst reviews network flow records and notices a compromised Linux server making outbound connections to an external host. Each connection lasts exactly 45 seconds, transfers roughly 2 KB, and then terminates; a new connection begins 15 seconds later. The destination IP changes every few hours among a pool of addresses in the same /24. The payload is fully encrypted and no standard application protocol headers are visible. Which technique is the attacker MOST likely using to maintain command-and-control while evading detection?

Hard
13

During an incident response engagement on a Linux server, you discover an attacker has established covert command and control using a custom backdoor communicating over raw ICMP sockets. Which network analysis method provides the most reliable detection mechanism for this specific covert channel regardless of packet payload obfuscation?

Medium
14

An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?

Medium

Frequently asked questions

What does the Detecting Exploitation and Covert Communication Tools domain cover on the GCIH exam?
Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.
How many questions are in this domain?
This page lists all 14 Detecting Exploitation and Covert Communication Tools questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Detecting Exploitation and Covert Communication Tools questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH detecting exploitation and covert communication tools Practice Questions