Courseiva

GCIH · domain

Network and Log Investigations

This GCIH domain covers evidence gathering and analysis across network captures and host/security logs. You must map activity to Windows Event IDs, interpret NetFlow and packet captures, and recognize tunneling or credential-theft patterns. Questions present short scenarios and ask which artifacts or indicators confirm the activity, so you need to know what each data source actually reveals.

21 questions4 easy11 medium6 hard

Focused practice

Practice Network and Log Investigations questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Network and Log Investigations

Be able to pick the right artifact for a scenario: Event IDs for credential attacks, flow data for traffic patterns, packet captures for protocol detail, and DNS logs for tunneling. The key skill is correlating multiple sources rather than trusting a single indicator.

Windows Security Event IDs for NTLM logon and explicit credential use, including 4624 logon types

NetFlow and flow records for identifying command-and-control, exfiltration volume, and lateral movement

Wireshark and tcpdump packet analysis of TLS handshakes, application payloads, and beaconing intervals

DNS query logs and packet inspection for tunneling indicators such as long labels and high query volume

Watch out for

Common Network and Log Investigations exam traps

  • ▸Confusing Event ID 4624 logon types, especially Type 3 network versus Type 10 RemoteInteractive, when tracing Pass-the-Hash activity.
  • ▸Assuming encrypted TLS traffic hides everything, ignoring metadata like certificate fields, JA3, SNI, and packet sizes and timing.
  • ▸Treating any large DNS query as tunneling, missing that volume, entropy, and TXT or NULL record abuse matter more.

Question index

All Network and Log Investigations questions (21)

Click any question to see the full explanation, or start a practice session above.

1

You are investigating an alert regarding a 'Beaconing' pattern. Which aspect of the network connection is most indicative of automated C2 communication versus human browsing activity?

Hard
2

A security analyst is reviewing a packet capture from a compromised host and observes a series of DNS queries for randomly generated subdomains of a single domain, each followed by a TXT record response containing encoded data. The queries occur at regular intervals of approximately 60 seconds. Which type of attack is most strongly indicated by this pattern?

Hard
3

An incident responder notices an unusual outbound connection from a workstation to an external IP address on TCP port 443. Packet capture analysis shows that the SSL/TLS handshake completes, but the subsequent application-layer data payload is fully encrypted and does not match standard HTTPS browser traffic patterns. Which log investigation method provides the most reliable approach to determine if this traffic represents malicious command and control activity?

Medium
4

An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?

Medium
5

An incident handler is analyzing a packet capture to identify command-and-control (C2) communication. Which two characteristics are most indicative of C2 traffic? (Choose two.)

Medium
6

An incident responder is analyzing a network capture to identify potential command-and-control (C2) communication. The capture shows a workstation making regular DNS queries to 'update.microsoft.com' every 60 seconds, each followed by a small HTTPS session to a different IP address. The HTTPS sessions use self-signed certificates and the User-Agent string is 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'. Which TWO of the following indicators most strongly suggest malicious C2 activity? (Choose two.)

Medium
7

An incident handler is examining a packet capture from a compromised workstation and observes a series of DNS queries for domains like 'a1b2c3d4e5.exfil.example.com', each followed by a large TXT response. The queries are sent at regular 30-second intervals, and the subdomains contain random-looking alphanumeric strings. Which of the following techniques is MOST likely being used by the attacker?

Medium
8

You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?

Medium
9

An incident handler is investigating a suspected data exfiltration on a Windows workstation. The SIEM generated an alert for a large outbound transfer to an unfamiliar IP address. The handler needs to determine which process initiated the connection. Which built-in Windows tool is most appropriate to correlate the active network connection to its owning process?

Medium
10

During an investigation of a suspected lateral movement attempt within an Active Directory environment, an incident handler needs to isolate authentication events involving Kerberos ticket-granting service (TGS) requests that indicate potential Kerberoasting activity. Which Windows Security Event Log ID should the analyst examine to identify abnormal requests for service principal names (SPNs) using weak encryption algorithms?

Hard
11

An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?

Medium
12

An incident handler is investigating a suspected compromised Windows workstation. They review Windows Security event logs and notice a large number of Event ID 4625 (An account failed to log on) followed by a single Event ID 4624 (An account was successfully logged on) from the same source IP within a short period. Which of the following best describes the activity?

Easy
13

An incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?

Medium
14

Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?

Easy
15

An incident handler is analyzing a PCAP and observes a series of TCP packets with the SYN flag set, followed by a single RST/ACK packet from the destination. What is the most likely explanation for this pattern?

Hard
16

An incident handler is examining a web server's access logs after a suspected SQL injection attempt. The log shows a request with a long URL containing multiple single quotes and 'UNION SELECT' statements. Which log field is most critical to correlate this request with other events to determine if the attack succeeded?

Medium
17

An analyst is investigating a suspected Pass-the-Hash attack within an Active Directory environment. Which TWO Windows Security Event Log IDs should the analyst examine to detect the use of stolen NTLM credential material for lateral movement? (Choose TWO)

Medium
18

Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?

Easy
19

An incident handler is triaging a suspected beaconing implant on a Windows workstation. NetFlow records show a repeating outbound connection to the same external IP address every 60 seconds, but the packets are only 200 bytes each, so no payload is captured. The handler wants to confirm the beacon's timing jitter and any command-and-control content without deploying a new agent to the endpoint. Which investigative approach BEST accomplishes this?

Hard
20

An incident handler is analyzing a packet capture and notices a high volume of TCP SYN packets sent to multiple ports on a single target host, with no corresponding SYN-ACK responses. The source IP is spoofed. What type of activity does this indicate?

Easy
21

During a network investigation, an incident responder notices a high volume of outbound DNS queries to a single external domain, with each query containing a long, random-looking subdomain. The queries occur at regular intervals of approximately 30 seconds. Which type of attack is most likely indicated?

Hard

Frequently asked questions

What does the Network and Log Investigations domain cover on the GCIH exam?
Be able to pick the right artifact for a scenario: Event IDs for credential attacks, flow data for traffic patterns, packet captures for protocol detail, and DNS logs for tunneling. The key skill is correlating multiple sources rather than trusting a single indicator.
How many questions are in this domain?
This page lists all 21 Network and Log Investigations questions in the GCIH question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network and Log Investigations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gcih GIAC-GCIH network and log investigations Practice Questions