Courseiva

GCIH · domain

Malware and AI-Assisted Investigations

This domain covers using AI tools during malware incidents while keeping human judgment in control. GCIH tests whether you can apply the incident handling lifecycle to AI-assisted hunting, validate AI output before acting, recognize adversarial manipulation of detection engines, and manage risks from unvetted models. Questions are scenario-based, asking you to pick the safest or most correct analyst action.

20 questions5 easy7 medium8 hard

Focused practice

Practice Malware and AI-Assisted Investigations questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Malware and AI-Assisted Investigations

You must integrate AI tools into the incident handling process without surrendering analyst judgment. The single most important thing: validate every AI-generated finding, command, and signature before acting on production systems, and treat AI output as an untrusted lead, not a conclusion.

Applying the incident handling lifecycle to AI-assisted malware hunting and response tasks

Validating AI-generated summaries, commands, and response steps before touching production systems

Recognizing adversarial inputs that poison or evade AI-powered detection engines

Assessing supply chain and integrity risks of unvetted AI models used for signature generation

Watch out for

Common Malware and AI-Assisted Investigations exam traps

  • ▸Executing AI-recommended containment or remediation commands on production hosts without first validating them in a lab or against known-good references
  • ▸Treating AI-generated malware analysis as authoritative and skipping independent verification with tools like sandboxes or hash lookups
  • ▸Assuming an AI detection engine is immune to evasion, ignoring adversarial inputs, data poisoning, and model supply chain risk

Question index

All Malware and AI-Assisted Investigations questions (20)

Click any question to see the full explanation, or start a practice session above.

1

An analyst notices that an AI-powered detection tool is flagging legitimate administrative PowerShell scripts as malicious. Which approach should the analyst take to improve model precision?

Medium
2

A junior analyst is using an AI-powered malware analysis tool to examine a suspicious executable. The tool provides a summary indicating that the file is 'likely malicious' with a confidence score of 65%. The analyst is unsure how to proceed. According to incident response best practices, what should the analyst do NEXT?

Easy
3

An analyst is training a machine learning model to classify malware families. Which data preparation technique is most critical to prevent bias in the classification results?

Medium
4

You are leading an incident response effort against a sophisticated adversary who uses AI-generated polymorphic malware that changes its code signature on each execution. Your team employs AI-assisted tools for detection and analysis. Which TWO of the following techniques are MOST effective for identifying and tracking this malware across multiple hosts? (Choose two.)

Medium
5

Which TWO of the following strategies are most effective when using AI tools to assist in the analysis of large-scale, automated malware logs?

Hard
6

A GCIH incident handler is investigating a Linux server that an AI-based anomaly detector flagged for unusual outbound traffic. The handler suspects the server is beaconing to a C2 server but the traffic is encrypted and the beacon interval appears randomized. The handler has a packet capture and wants to apply a technique that can identify the beaconing pattern despite the randomization. Which approach should the handler use?

Hard
7

Refer to the exhibit. The log shows a low-confidence alert from an AI tool. How should an incident responder proceed?

Medium
8

Which capability is most important for a modern incident response team to maintain when integrating AI tools into their workflow?

Medium
9

A junior incident handler is reviewing an alert from an AI-powered email security gateway that flagged a message as a likely AI-generated phishing attempt. The gateway's model outputs a confidence score but no explanation. The handler wants to gather corroborating evidence from the message headers and body to support the classification before escalating. Which artifact would best help the handler verify that the message was generated or augmented by an AI tool?

Easy
10

An attacker has compromised a host and established persistence using a malicious scheduled task that executes an encoded PowerShell command. The command downloads a second-stage payload from a legitimate cloud storage service. Your AI-assisted EDR has flagged the activity but provided only a low-confidence alert. As the incident responder, you need to determine the next investigative step. Which of the following actions is MOST likely to yield actionable intelligence about the second-stage payload?

Hard
11

An AI-assisted investigation tool summarizes a week of EDR telemetry and reports that a workstation 'likely performed credential dumping.' The summary cites no specific process, command line, or timestamp. What should the incident handler do first?

Hard
12

When investigating an AI-generated spear-phishing campaign, what is the most effective indicator to look for that suggests the content was created by a Large Language Model (LLM)?

Hard
13

An analyst discovers that an attacker is using AI to dynamically change the command-and-control (C2) infrastructure based on defensive responses. Which IR strategy is best suited to disrupt this behavior?

Hard
14

Which THREE of the following are essential components of an effective AI-assisted malware hunting strategy?

Hard
15

During a malware investigation, you discover that the adversary is using an AI model to generate domain names for its command-and-control (C2) infrastructure. The domains appear legitimate and are registered in bulk. Your AI-assisted threat hunting platform uses domain generation algorithm (DGA) detection but is missing these domains. Which of the following is the MOST likely reason for the detection failure?

Hard
16

An analyst uses an AI assistant to summarize a malware report and generate response steps. Before executing any recommended commands on production systems, what is the most important action?

Easy
17

Which of the following is a classic example of an 'adversarial' attack against an AI-powered detection engine?

Easy
18

Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?

Easy
19

Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is the most appropriate next step for an incident handler?

Medium
20

During an incident, you capture a suspicious binary that evades static detection. You submit it to an AI-based malware analysis platform, which returns a confidence score of 0.55 and flags 'possible packer.' The binary has not yet been detonated. What should you do next?

Medium

Frequently asked questions

What does the Malware and AI-Assisted Investigations domain cover on the GCIH exam?
You must integrate AI tools into the incident handling process without surrendering analyst judgment. The single most important thing: validate every AI-generated finding, command, and signature before acting on production systems, and treat AI output as an untrusted lead, not a conclusion.
How many questions are in this domain?
This page lists all 20 Malware and AI-Assisted Investigations questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Malware and AI-Assisted Investigations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH malware and ai assisted investigations Practice Questions