Courseiva

GCIH Malware and AI-Assisted Investigations Practice Question

During an incident, you capture a suspicious binary that evades static detection. You submit it to an AI-based malware analysis platform, which returns a confidence score of 0.55 and flags 'possible packer.' The binary has not yet been detonated. What should you do next?

⚠ Common exam trap

The trap here is assuming a low AI confidence score means the file is benign and can be closed without further analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit the binary to a dynamic sandbox and correlate its behavior with network and endpoint telemetry.

An AI confidence score of 0.55 with a packer flag is inconclusive, so the responder must validate the hypothesis with behavioral evidence. Dynamic sandbox detonation exposes the malware's actual actions, which can then be correlated with network and endpoint telemetry to confirm malicious intent. Only after corroboration should containment or escalation occur, avoiding both premature blocking and premature dismissal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Submit the binary to a dynamic sandbox and correlate its behavior with network and endpoint telemetry.

    Why this is correct

    A moderate AI confidence score combined with a packer flag is a hypothesis, not a conclusion. Detonating the sample in a sandbox reveals actual behaviors such as persistence, C2 callbacks, and file system changes, which can be correlated with existing network and endpoint logs. This evidence-based validation is the correct next step before containment or escalation decisions.

  • ✗

    Close the case as a false positive because the confidence score is below 0.75.

    Why it's wrong here

    Treating a sub-0.75 score as automatically benign ignores the possibility of a true positive with weak static signals. The packer flag itself is suspicious and warrants further investigation. Closing the case without dynamic analysis or telemetry correlation could allow an active intrusion to continue undetected, violating basic incident handling principles of verification before dismissal.

  • ✗

    Immediately block the file hash across all endpoints based on the AI flag.

    Why it's wrong here

    Blocking on a 0.55 confidence score with only a packer indication risks a false positive and operational disruption. Packing is common in legitimate software, so an unverified AI flag alone does not justify enterprise-wide blocking. The analyst should first gather corroborating evidence through dynamic analysis and other telemetry before taking containment actions that could affect business operations.

  • ✗

    Extract the binary's strings and import table, then make a final determination based on those static artifacts.

    Why it's wrong here

    Static artifacts from a packed binary are largely meaningless because the original code is compressed or encrypted. Strings and import tables may be obfuscated or minimal, leading to an inaccurate conclusion. The AI already performed static analysis and returned a low-confidence result, so repeating static-only review adds little value. Dynamic analysis is needed to observe real behavior.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.