GCIH Integrating LLMs with Offensive Operations Practice Question
Which TWO of the following are significant risks associated with using LLMs for automated malware analysis?
⚠ Common exam trap
Candidates tend to overlook the risk of confident hallucinations, assuming that automated AI reports are always technically accurate regarding binary structures and code analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inadvertent disclosure of proprietary code or indicators of compromise.
Automated malware analysis with LLMs carries risks related to data leakage and the inherent inaccuracy of AI models. If the model is not properly sandboxed, it may inadvertently leak indicators of compromise (IOCs) or sensitive binary analysis results to the provider. Additionally, the tendency of models to hallucinate or misinterpret complex obfuscation patterns can lead to incorrect analysis reports, which may cause responders to overlook actual threats or pursue useless remediation strategies during an investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The model will automatically execute the malware and infect the local network.
Why it's wrong here
LLMs generally lack the ability to execute binary code. The risk is not that the model will infect the network itself, but rather that the model might provide misleading information about the malware's capabilities, causing the responder to make poor decisions that lead to a wider system compromise elsewhere.
- ✓
Inadvertent disclosure of proprietary code or indicators of compromise.
Why this is correct
Submitting binary analysis data or specific malware fragments to an external LLM puts that information into the provider's domain. If these contain proprietary code structures or highly specific indicators unique to the organization's network, they could be exposed, compromising the current defense efforts and revealing sensitive threat intelligence publicly.
- ✓
Generation of confident but incorrect analysis reports.
Why this is correct
LLMs are prone to hallucination. When analyzing sophisticated malware, they might confidently misidentify the C2 infrastructure or the function of a binary. This false sense of certainty can lead responders to focus on the wrong incident indicators, delaying containment and wasting valuable time during a critical security event.
- ✗
The LLM will automatically report the malware to the vendor for analysis.
Why it's wrong here
While some security products use LLMs to automate reporting, the LLM itself does not typically have an automated reporting function that sends data to third-party security vendors. The risk is instead related to the ingestion of data by the model provider, rather than proactive reporting of the threat to other parties.
- ✗
The model will increase the time required to complete the analysis.
Why it's wrong here
LLMs are generally designed to decrease the time required for analysis by summarizing complex data quickly. If the model increases the time spent, it is an inefficiency issue, not a fundamental security risk. The primary risks remain the accuracy of the output and the potential for sensitive data exposure.
About these practice questions
One of 322 original GCIH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.