Courseiva

GCIH Integrating LLMs with Offensive Operations Practice Question

Which TWO of the following are significant risks associated with using LLMs for automated malware analysis?

⚠ Common exam trap

Candidates tend to overlook the risk of confident hallucinations, assuming that automated AI reports are always technically accurate regarding binary structures and code analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inadvertent disclosure of proprietary code or indicators of compromise.

Automated malware analysis with LLMs carries risks related to data leakage and the inherent inaccuracy of AI models. If the model is not properly sandboxed, it may inadvertently leak indicators of compromise (IOCs) or sensitive binary analysis results to the provider. Additionally, the tendency of models to hallucinate or misinterpret complex obfuscation patterns can lead to incorrect analysis reports, which may cause responders to overlook actual threats or pursue useless remediation strategies during an investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The model will automatically execute the malware and infect the local network.

    Why it's wrong here

    LLMs generally lack the ability to execute binary code. The risk is not that the model will infect the network itself, but rather that the model might provide misleading information about the malware's capabilities, causing the responder to make poor decisions that lead to a wider system compromise elsewhere.

  • ✓

    Inadvertent disclosure of proprietary code or indicators of compromise.

    Why this is correct

    Submitting binary analysis data or specific malware fragments to an external LLM puts that information into the provider's domain. If these contain proprietary code structures or highly specific indicators unique to the organization's network, they could be exposed, compromising the current defense efforts and revealing sensitive threat intelligence publicly.

  • ✓

    Generation of confident but incorrect analysis reports.

    Why this is correct

    LLMs are prone to hallucination. When analyzing sophisticated malware, they might confidently misidentify the C2 infrastructure or the function of a binary. This false sense of certainty can lead responders to focus on the wrong incident indicators, delaying containment and wasting valuable time during a critical security event.

  • ✗

    The LLM will automatically report the malware to the vendor for analysis.

    Why it's wrong here

    While some security products use LLMs to automate reporting, the LLM itself does not typically have an automated reporting function that sends data to third-party security vendors. The risk is instead related to the ingestion of data by the model provider, rather than proactive reporting of the threat to other parties.

  • ✗

    The model will increase the time required to complete the analysis.

    Why it's wrong here

    LLMs are generally designed to decrease the time required for analysis by summarizing complex data quickly. If the model increases the time spent, it is an inefficiency issue, not a fundamental security risk. The primary risks remain the accuracy of the output and the potential for sensitive data exposure.

About these practice questions

One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.