Courseiva

GCIH Malware and AI-Assisted Investigations Practice Question

During a malware investigation, you discover that the adversary is using an AI model to generate domain names for its command-and-control (C2) infrastructure. The domains appear legitimate and are registered in bulk. Your AI-assisted threat hunting platform uses domain generation algorithm (DGA) detection but is missing these domains. Which of the following is the MOST likely reason for the detection failure?

⚠ Common exam trap

The trap here is assuming that DGA detection can automatically adapt to AI-generated domains, when in fact it requires retraining on new data to recognize evolving patterns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DGA detection model was trained on older DGA families and cannot recognize AI-generated patterns.

AI-generated domains may not match the patterns learned by a DGA detection model trained on traditional algorithms. The model's inability to recognize novel AI-generated patterns is the most likely cause. Other factors like registration, encryption, or length are less relevant to DGA detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The DGA detection model was trained on older DGA families and cannot recognize AI-generated patterns.

    Why this is correct

    AI-generated domains may follow different statistical patterns than traditional DGAs. If the detection model was trained primarily on known DGA families, it may not generalize to novel AI-generated domains. This is a common limitation of machine learning models when faced with evolving threats, requiring retraining with new data.

  • ✗

    The AI model generates domains that are too short to be analyzed by the DGA detection.

    Why it's wrong here

    Domain length is not a primary factor for DGA detection; many DGAs generate domains of varying lengths. AI-generated domains could be of any length. The failure is more likely due to the pattern being unrecognized by the model, not the length itself.

  • ✗

    The C2 traffic is encrypted, preventing the DGA detection from analyzing the domain names.

    Why it's wrong here

    DGA detection analyzes domain names, not traffic content. Encryption of C2 traffic does not affect the ability to inspect domain names in DNS queries or TLS SNI. The detection failure is likely due to the domain generation pattern, not encryption.

  • ✗

    The domains are registered with legitimate registrars, so they are automatically whitelisted.

    Why it's wrong here

    Legitimate registration does not imply whitelisting. Many malicious domains are registered through legitimate registrars. Whitelisting is typically based on reputation or allowlists, not solely on the registrar. This is unlikely to be the primary reason for detection failure.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.