Courseiva

GCIH Endpoint Attack and Pivoting Practice Question

What is the primary function of the 'Token Manipulation' technique in Windows pivoting?

⚠ Common exam trap

Candidates confuse token manipulation with password dumping. They assume the attacker must crack a password to impersonate a user, rather than realizing the token already exists in memory for legitimate use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To impersonate another user's security context.

Token manipulation involves stealing an access token from a process running as a different user (e.g., SYSTEM or an Administrator) and using it to spawn a new process. This allows the attacker to elevate their privileges or move laterally as a different user. Understanding this technique is vital for incident handlers because it explains how attackers maintain high-level access without knowing user passwords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To hide files in a hidden directory.

    Why it's wrong here

    Token manipulation has nothing to do with file storage or filesystem obfuscation. It is strictly about process identity and authentication. Hiding files is a separate persistence or exfiltration technique that does not involve interacting with the Windows security subsystem or impersonating other user contexts on the host.

  • ✗

    To bypass user authentication prompts.

    Why it's wrong here

    While it allows an attacker to act as another user, it does not 'bypass' authentication prompts in the way a password bypass would. It works by stealing an existing session token that has already been authenticated, effectively 'inheriting' the rights of that user session without requiring an interactive login.

  • ✓

    To impersonate another user's security context.

    Why this is correct

    Impersonation is the core goal of token manipulation. By taking the security token of a higher-privileged process, the attacker can execute commands with those elevated permissions. This is a common and powerful technique used during lateral movement to gain control over critical system components and administrative resources.

  • ✗

    To encrypt the memory of a running process.

    Why it's wrong here

    Encrypting process memory is not a standard technique for pivoting. Attackers generally want to read or inject into process memory to steal information or code, not encrypt it. Encrypting memory would crash the process and trigger stability alerts, failing the attacker's objective of stealth and persistence.

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.