Courseiva

GCIH Incident Response and Cyber Investigation Practice Question

During an investigation, you observe an attacker using 'living-off-the-land' (LotL) techniques. Why is it difficult to detect this activity using traditional signature-based antivirus?

⚠ Common exam trap

Candidates often assume that because the binary is 'trusted' or 'signed,' it cannot be used for malicious purposes, leading them to overlook the malicious intent hidden within the command-line arguments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The tools are trusted binaries and the malicious intent is in the parameters.

Living-off-the-land attacks use legitimate, signed system binaries (like PowerShell, wmic, or certutil) to perform malicious actions. Since the tools themselves are trusted components of the operating system, antivirus software rarely flags them as malicious. Detecting LotL requires behavioral analysis, command-line logging, and monitoring for anomalous execution patterns rather than relying on file signatures, which are ineffective against tools that are inherently part of the system's baseline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    These binaries are encrypted on the disk, preventing antivirus from scanning them.

    Why it's wrong here

    System binaries are not encrypted in a way that prevents AV scanning. Antivirus tools can read these files easily; the challenge is that the files themselves are known-good, trusted binaries, and the antivirus engine does not recognize that the intent of the execution is malicious in the given context.

  • ✗

    The tools operate entirely in volatile memory and never touch the disk.

    Why it's wrong here

    While some LotL techniques are fileless, many use existing binaries stored on the disk. The difficulty is not the lack of files, but the fact that the files themselves are legitimate, trusted Microsoft utilities, meaning the antivirus does not trigger an alert on the binary's presence or its execution.

  • ✓

    The tools are trusted binaries and the malicious intent is in the parameters.

    Why this is correct

    LotL techniques leverage legitimate tools that are signed and trusted by the OS. Antivirus signatures are designed to identify known malicious code; because the binaries themselves are benign, the AV ignores them. Detection must focus on the suspicious flags and command-line arguments, which AV does not typically inspect.

  • ✗

    Antivirus software is only capable of detecting malware written in assembly language.

    Why it's wrong here

    Modern antivirus solutions detect malware written in a variety of languages, including high-level languages like C# and Python. The limitation in detecting LotL is not the language of the tool, but the fact that the tools being used are standard OS utilities that are excluded from security alerts.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.