Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

Exhibit

JSON policy: {"rules": [{"action": "deny", "process": "powershell.exe", "arguments": "-enc"}]}

Refer to the exhibit. An attacker bypasses this policy. Why did this control fail?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy only filters for one specific argument variation.

The policy specifically blocks -enc, but PowerShell supports multiple aliases and variations like -encodedcommand, -e, and -en. Security controls that rely on string matching for specific command-line arguments are brittle because attackers can easily use different syntax or encoding to achieve the same result. Effective detection must look for the behavior of encoded execution regardless of the specific argument shorthand used in the command line.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PowerShell was not fully patched to the latest version.

    Why it's wrong here

    Patching does not influence how command-line arguments are interpreted by the PowerShell engine. The vulnerability lies in the logic of the filter itself, which is too specific and fails to account for the numerous ways the same intent can be expressed syntactically.

  • ✓

    The policy only filters for one specific argument variation.

    Why this is correct

    The policy is flawed because it only looks for the '-enc' string. PowerShell accepts various abbreviations for encoded commands, such as '-encoded', '-e', and '-en'. By using a different variation, the attacker effectively circumvents the filter, demonstrating the weakness of signature-based argument blocking.

  • ✗

    The system was not rebooted after the policy was applied.

    Why it's wrong here

    Policy enforcement for process execution monitoring typically happens in real-time at the kernel or endpoint level and does not require a system reboot to take effect. If the policy was correctly deployed, a reboot would not change the fact that the filter logic is fundamentally incomplete.

  • ✗

    The policy only blocks 'powershell.exe' and not 'pwsh.exe'.

    Why it's wrong here

    While it is true that pwsh.exe is a separate binary, the exhibit specifically shows a rule targeting powershell.exe. The primary failure is the argument matching logic, not the binary choice. Even if both were blocked, the argument variation issue would remain the primary bypass vector.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.