Courseiva

GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques

Which of the following is a sign of 'Domain Fronting' in network traffic logs?

⚠ Common exam trap

Candidates look for mismatched source and destination IP addresses, failing to notice the critical discrepancy between the external SNI and the internal HTTP Host header.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A mismatch between the SNI and the internal HTTP Host header.

Domain fronting uses high-reputation domains (like CDNs) to hide the true destination of malicious traffic. The initial request looks like it is going to a trusted domain, but the HTTP Host header inside the encrypted tunnel points to the attacker's server. Detecting this requires deep packet inspection or analysis of SSL/TLS metadata, which is critical for identifying covert C2 channels that masquerade as legitimate web traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A mismatch between the SNI and the internal HTTP Host header.

    Why this is correct

    In domain fronting, the SNI (Server Name Indication) presented in the TLS handshake belongs to a reputable CDN, but the actual HTTP request inside the encrypted stream contains a different Host header. Detecting this mismatch is the most reliable way to identify domain fronting activity in proxy logs.

  • ✗

    Large volumes of traffic to a single domain over port 443.

    Why it's wrong here

    High volumes of HTTPS traffic are common for many legitimate services like cloud storage or video streaming. Using traffic volume as an indicator of domain fronting would lead to a significant number of false positives and is not a reliable method for identifying this specific evasion technique.

  • ✗

    Unusually slow download speeds for legitimate files.

    Why it's wrong here

    Performance issues like slow download speeds are typically related to network congestion or server-side limitations. They are not inherent indicators of domain fronting, which is a technique designed to blend in with normal traffic patterns rather than cause noticeable performance degradation for the end user.

  • ✗

    Repeated failed authentication attempts to the CDN.

    Why it's wrong here

    Domain fronting does not involve the CDN's authentication mechanism directly. The CDN simply proxies the request to the attacker's hidden origin server. Failed authentication attempts are indicative of credential stuffing or brute force, not the use of a domain fronting technique for C2 communication.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.