Courseiva

GCIH · topic practice

Detecting Exploitation and Covert Communication Tools practice questions

This GCIH domain covers recognizing attacker tradecraft on hosts and networks: suspicious process lineage, covert channels tunneled through ICMP, DNS, or HTTP, and the command-line evidence left behind. Questions present real command output, packet captures, or process listings and ask you to identify attacker intent, the tool in use, or the correct investigative step.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Detecting Exploitation and Covert Communication Tools

What the exam tests

What to know about Detecting Exploitation and Covert Communication Tools

Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.

Correlating Parent Process ID with execution path to spot process masquerading or injection

Detecting covert C2 tunneled over ICMP echo payloads, DNS queries, or nonstandard ports

Using tcpdump, Wireshark, netstat, ss, and lsof to expose covert channels

Reading Linux command output to infer attacker intent such as persistence or exfiltration

Watch out for

Common Detecting Exploitation and Covert Communication Tools exam traps

  • ▸Judging a process malicious by name alone instead of validating PPID, path, and parent-child lineage
  • ▸Assuming ICMP is benign and skipping payload inspection of echo request and reply data
  • ▸Confusing legitimate administrative tooling with attacker tradecraft without checking timing, volume, or destination

Practice set

Detecting Exploitation and Covert Communication Tools questions

20 questions · select your answer, then reveal the explanation

An analyst observes a series of outbound HTTPS connections to an unknown external IP address. The connections occur at exact 300-second intervals and maintain a consistent packet size. Which detection strategy is most effective for identifying this potential covert channel?

Refer to the exhibit. An analyst identifies this HTTP response during an investigation. Based on the Set-Cookie header content, what tool or technique is potentially being used by the threat actor?

Exhibit

HTTP/1.1 200 OK
Server: Apache/2.4.41
Date: Mon, 12 Oct 2023 10:00:00 GMT
Content-Type: text/html
Content-Length: 452
Set-Cookie: session=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiYWRtaW4ifQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
Connection: close

Which TWO of the following indicators are highly suspicious when analyzing workstation memory for rootkit activity?

Which tool is primarily used for identifying and analyzing covert communication channels by inspecting the timing and entropy of network packets?

Which THREE of the following are considered hallmarks of steganography when used to hide data in network traffic?

Refer to the exhibit. What is the effect of this AWS policy on access to the sensitive-data S3 bucket?

Exhibit

JSON policy: {
  "effect": "deny",
  "action": "s3:GetObject",
  "resource": "arn:aws:s3:::sensitive-data/*",
  "condition": {
    "StringNotIpAddress": {
      "aws:SourceIp": "192.168.1.0/24"
    }
  }
}
Question 7hardmulti select
Read the full DNS explanation →

An incident responder is investigating a compromised Windows host and suspects the presence of a covert command and control (C2) channel utilizing DNS tunneling. Which TWO registry locations or artifact categories should the analyst examine to identify DNS client cache activity and persistence associated with tunneling software?

During an incident response engagement on a Linux server, you discover suspicious outbound traffic communicating over raw sockets to an external IP address. The system administrator claims no custom applications are installed. Which utility should you run to inspect the process owning these raw socket file descriptors?

An incident responder is analyzing a memory dump from a compromised Windows 10 host. The responder suspects a rootkit is hiding a malicious driver. Which Volatility 3 plugin should be used to list loaded kernel modules and detect unlinked or hidden drivers?

Question 10mediummultiple choice
Read the full DNS explanation →

An incident responder is examining a Windows workstation suspected of being part of a botnet. Network logs show periodic DNS queries for long, random-looking subdomains under the domain 'evil-c2.com'. The queries occur every 60 seconds. Which technique is the attacker most likely using?

Question 11easymultiple choice
Read the full DNS explanation →

A security analyst notices that a user's workstation is communicating with an external IP address on port 53, but the traffic is not standard DNS. The packets are larger than typical DNS queries and contain binary data. Which type of covert channel is most likely being used?

An incident responder is investigating a suspected covert channel on a Linux server. The responder observes outbound traffic that uses the TCP protocol but does not match any known application signatures. The traffic is encrypted and sent to an external IP address on port 443. Which two indicators would suggest that this is a covert channel established by a tool like Cobalt Strike? (Choose two.)

An incident responder is analyzing a Linux server that is suspected of being compromised. The server is exhibiting unusual outbound network traffic. Which TWO of the following commands would be most useful to identify processes that have established network connections? (Choose two.)

An incident responder is examining a memory dump from a compromised Windows host. The responder suspects that an attacker used a reflective DLL injection technique to load a malicious payload. Which artifact in memory would best confirm this?

An adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?

Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?

Exhibit

C:\> vssadmin list shadows
vssadmin 1.1 - Volume Shadow Copy Service administrative command-line tool
(C) Copyright 2001-2013 Microsoft Corp.

Contents of shadow copy set ID: {abc12345-1234-abcd-1234-1234567890ab}
   Contained 1 shadow copy at creation time: 10/12/2023 11:00:00 AM
      Shadow Copy ID: {xyz09876-4321-dcba-4321-0987654321zy}
      Original Volume: (C:)\\?\Volume{00000000-0000-0000-0000-000000000000}\
      Shadow Copy Volume: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1

An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?

When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?

An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?

Which THREE actions are effective at identifying hidden 'living-off-the-land' (LotL) binary usage in a compromised system?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Detecting Exploitation and Covert Communication Tools sessions

Start a Detecting Exploitation and Covert Communication Tools only practice session

Every question in these sessions is drawn from the Detecting Exploitation and Covert Communication Tools domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Detecting Exploitation and Covert Communication Tools?
Be able to read process listings and packet captures and explain what the attacker is doing. The single most important skill is validating process lineage through PPID and execution path, then confirming covert channels by inspecting protocol payloads rather than trusting port or protocol conventions.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Detecting Exploitation and Covert Communication Tools questions in a focused session?
Yes — the session launcher on this page draws every question from the Detecting Exploitation and Covert Communication Tools domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.