Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

What is the primary purpose of 'Time Stomping' during a post-exploitation phase?

⚠ Common exam trap

Candidates assume time stomping is used to destroy logs or accelerate file deletion, missing its precise forensic purpose of matching file system timelines.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To blend malicious files into the existing file system timeline.

Time stomping involves modifying the timestamp attributes of files—specifically Created, Accessed, Written, and Mapped (CAWM) times—to match surrounding system files. This technique is designed to hide the presence of malicious files from forensic investigators who look for outliers in file system timelines. By understanding this, defenders know that relying solely on standard file system timestamps during an investigation is insufficient and requires secondary validation methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To crash the file system and hide malicious processes.

    Why it's wrong here

    Time stomping does not affect the stability of the file system and is not intended to cause system crashes. It is a stealth technique purely focused on metadata manipulation to deceive forensic analysis, rather than a disruptive or destructive activity aimed at system availability.

  • ✗

    To bypass file integrity monitoring (FIM) signatures.

    Why it's wrong here

    File integrity monitoring systems typically track file hashes, not timestamps. Modifying timestamps does not change the file's hash, meaning it will not bypass FIM systems that are configured correctly to detect unauthorized changes to protected files or binary images.

  • ✓

    To blend malicious files into the existing file system timeline.

    Why this is correct

    Time stomping is used to manipulate file metadata so that malicious files appear to be legitimate system files created long ago. This makes it significantly harder for human investigators to find files created during the window of compromise when searching for suspicious indicators based on time.

  • ✗

    To increase the privilege level of the attacker.

    Why it's wrong here

    Time stomping is a defensive evasion technique, not a privilege escalation technique. It does not provide the attacker with higher access rights, nor does it interact with the Windows access control model. Its sole purpose is to evade detection by forensic auditors or automated timelines.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.