GCIH Malware and AI-Assisted Investigations Practice Question
Exhibit
EXHIBIT: [2023-10-12 10:00:01] INFO: Model_Detection_Alpha: Potential C2 beaconing detected from 10.0.0.5 to 192.0.2.1:8080. [2023-10-12 10:00:05] WARN: Model_Confidence_Score: 0.45. [2023-10-12 10:00:10] INFO: Suggestion: Isolate host 10.0.0.5 immediately.
Refer to the exhibit. The log shows a low-confidence alert from an AI tool. How should an incident responder proceed?
⚠ Common exam trap
Candidates often assume that a low-confidence alert can be ignored or automatically dismissed, failing to realize that even 'low' probability threats still require human triage to confirm or rule out malicious activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct manual investigation of the host and network traffic to verify.
With a confidence score of 0.45, the AI is expressing high uncertainty, effectively indicating that the detection is not reliable enough for automated action. The responder must perform a manual investigation—such as checking firewall logs, host artifacts, or process trees—to validate the alert before taking disruptive actions. This ensures that the incident response process remains grounded in high-fidelity evidence rather than reacting to 'noisy' but potentially incorrect AI-generated suggestions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Follow the suggestion and isolate the host as instructed by the system.
Why it's wrong here
The confidence score is below 0.5, which is statistically significant in terms of unreliability. Automating the isolation of a host based on such low confidence is irresponsible and will likely result in a false positive, causing unnecessary business interruption. Human verification is a non-negotiable step before performing such a high-impact remediation action.
- ✓
Conduct manual investigation of the host and network traffic to verify.
Why this is correct
Manual validation is the only safe way to handle low-confidence AI alerts. By verifying the network traffic patterns and host process logs, the responder can determine if the alert is a genuine threat or a statistical anomaly. This preserves the operational uptime while ensuring that the organization's security posture remains robust and accurate.
- ✗
Log the event as a false positive and disable the detection rule.
Why it's wrong here
A low-confidence score does not mean the event is definitely a false positive; it just means the model is uncertain. Disabling the rule is a dangerous overreaction that leaves the environment exposed. The alert should be treated as a lead for further investigation, not as a conclusive determination that the rule is flawed.
- ✗
Wait for the AI to provide more logs before making a decision.
Why it's wrong here
Passive observation is not an acceptable incident response strategy. If an alert is generated, it must be triaged. The responder must take active steps to validate the event using external data sources, rather than waiting for the AI to generate more potentially inconclusive data which will not resolve the underlying uncertainty of the initial alert.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.