dc dotCreds
GIAC Certified Incident Handler Practice Test

GIAC GCIH Practice Test

Start today’s free 10-question GIAC GCIH set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 24, 2026, 12:27 AM CDT

Go Pro - One Time Unlock

Unlock the full GCIH bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 GIAC GCIH questions

Use this GIAC GCIH practice test to review GIAC Certified Incident Handler. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Web Application API Attacks Web and API attacks

An image-processing API accepts arbitrarily large uploads and permits each authenticated user to launch unlimited concurrent transformations. Attackers create thousands of expensive jobs with valid accounts until CPU and storage are exhausted. Which control best addresses the primary API risk?

Concept tested:
Question 2 of 10
Objective Network and Log Investigations Incident response and investigation

A suspected beacon appears as one HTTPS request every 60 seconds in firewall logs, but the proxy logs retain full URLs and the endpoint DNS cache is still available. What is the most useful next correlation step?

Concept tested:
Question 3 of 10
Objective Attacking Passwords Credential and cloud attacks

A consumer portal sees successful logins for 600 accounts within minutes. Each account used a different password, the usernames and passwords match pairs in a newly leaked breach from an unrelated retailer, and failed guesses are minimal. Which attack is most likely?

Concept tested:
Question 4 of 10
Objective SMB Security Scanning and exploitation

A legacy appliance can communicate only with SMB1. The organization has disabled SMB1 on Windows file servers, and the appliance vendor offers a supported SMB3 firmware update. What is the strongest remediation?

Concept tested:
Question 5 of 10
Objective Integrating LLMs with Offensive Operations Post-exploitation and AI

A SOC uses an LLM to summarize malware evidence that may contain customer secrets. Which architecture best reduces data-governance risk while retaining analytical value?

Concept tested:
Question 6 of 10
Objective Detecting Exploitation and Covert Communications Tools Scanning and exploitation

An analyst finds `ncat -l -k 4444` running under an unusual service account. Which behavior is most consistent with those options?

Concept tested:
Question 7 of 10
Objective Detecting Evasive and Post-Exploitation Techniques Post-exploitation and AI

An analyst sees a PowerShell command and immediately labels it “Defense Evasion.” What additional reasoning is required for a defensible ATT&CK mapping?

Concept tested:
Question 8 of 10
Objective Malware and AI Assisted Investigations Incident response and investigation

An endpoint is actively beaconing, and memory-resident malware is suspected. The system is already network-isolated but remains powered on. Which evidence should be prioritized before a reboot if the goal is to preserve volatile behavior?

Concept tested:
Question 9 of 10
Objective Understanding Passwords Credential and cloud attacks

A new password verifier currently requires 12 characters, one uppercase, one lowercase, one number, one symbol, and a mandatory 60-day change. It does not check chosen passwords against known breached values. Which redesign is most consistent with current NIST guidance?

Concept tested:
Question 10 of 10
Objective Exploiting Insecure Web Application References Web and API attacks

A mobile client sends `{"accountId":"A-9007","amount":250}` to `/transfer`. Changing `accountId` to another customer’s value causes the transfer to debit that customer. The server validates authentication but not ownership of `accountId`. Which control is required?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
GCIH Pro $4.99 one-time

Unlock all 200 GIAC GCIH questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question GCIH PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, CompTIA SecurityX, Certified Ethical Hacker, GIAC GCIH, ISC2 CISSP, ISC2 CCSP, ISACA CISM, ISACA CRISC, ISACA CISA, AWS Security Specialty, Cisco CCST Cybersecurity, Cisco CCST Networking, Cisco CyberOps Associate, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full GCIH bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily GCIH practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily GIAC GCIH set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 An image-processing API accepts arbitrarily large uploads and permits each authenticated user to launch unlimited concurrent transformations. Attackers create thousands of expensive jobs with valid accounts until CPU and storage are exhausted. Which control best addresses the primary API risk?

Answer choices

  1. A. Enforce request-size, concurrency, per-user quota, execution-time, and resource-consumption limits appropriate to the operation.
  2. B. Require stronger passwords for the accounts submitting the jobs.
  3. C. Rename the transformation endpoint so automated clients cannot discover it.
  4. D. Permit unlimited jobs but add more detailed error messages when capacity is exhausted.

Correct answer

Enforce request-size, concurrency, per-user quota, execution-time, and resource-consumption limits appropriate to the operation.

APIs should limit resource-intensive operations across dimensions such as payload size, execution time, concurrency, and per-client quota. Authentication alone does not prevent abuse of expensive legitimate functionality.

Wrong-answer review

  • B. Require stronger passwords for the accounts submitting the jobs.: Incorrect. The requests are already authenticated; the problem is unbounded resource consumption through valid operations.
  • C. Rename the transformation endpoint so automated clients cannot discover it.: Incorrect. Endpoint obscurity does not constrain resource use once the API is known.
  • D. Permit unlimited jobs but add more detailed error messages when capacity is exhausted.: Incorrect. Better errors do not prevent deliberate exhaustion and may provide attackers with additional feedback.

Extra learning features

Why candidates miss this

The provided distractor, ‘Require stronger passwords for the accounts submitting the jobs,’ is a standard security practice but doesn't address the core issue of unbounded resource consumption. The decisive clue is the API's design allowing unlimited jobs, highlighting the need for resource constraints, not just authentication. Likely wrong answer: Require stronger passwords for the accounts submitting the jobs. Review focus: OWASP API Security Top 10 2023

Why this matters

Exhausting CPU and storage through automated jobs due to unrestricted API access can lead to service outages, impacting revenue and customer trust. Implementing resource limits prevents this disruption, ensuring operational stability and maintaining business continuity. This directly impacts the company's ability to fulfill its service obligations.

Objective/domain: Web and API attacks

Source: OWASP API Security Top 10 2023

Question 2 A suspected beacon appears as one HTTPS request every 60 seconds in firewall logs, but the proxy logs retain full URLs and the endpoint DNS cache is still available. What is the most useful next correlation step?

Answer choices

  1. A. Block all HTTPS traffic from the subnet before examining the higher-fidelity logs.
  2. B. Align the periodic connections with proxy URL/host data and endpoint DNS resolution to determine whether the same process is repeatedly contacting a consistent external service.
  3. C. Treat the 60-second interval as proof of command-and-control without additional evidence.
  4. D. Ignore the proxy and DNS evidence because encrypted HTTPS prevents useful investigation.

Correct answer

Align the periodic connections with proxy URL/host data and endpoint DNS resolution to determine whether the same process is repeatedly contacting a consistent external service.

Objective/domain: Incident response and investigation

Source: NIST SP 800-92: Guide to Computer Security Log Management

Question 3 A consumer portal sees successful logins for 600 accounts within minutes. Each account used a different password, the usernames and passwords match pairs in a newly leaked breach from an unrelated retailer, and failed guesses are minimal. Which attack is most likely?

Answer choices

  1. A. Password spraying, because many accounts were targeted in a short period.
  2. B. Online brute force, because every successful login proves repeated exhaustive guessing.
  3. C. Credential stuffing using previously compromised username/password pairs from another service.
  4. D. Pass-the-hash, because passwords from one service can be used directly as NTLM hashes against another web portal.

Correct answer

Credential stuffing using previously compromised username/password pairs from another service.

Objective/domain: Credential and cloud attacks

Source: NIST SP 800-63B-4: Authentication and Authenticator Management

Question 4 A legacy appliance can communicate only with SMB1. The organization has disabled SMB1 on Windows file servers, and the appliance vendor offers a supported SMB3 firmware update. What is the strongest remediation?

Answer choices

  1. A. Upgrade the appliance to the supported SMB3 firmware and keep SMB1 disabled on the file servers.
  2. B. Re-enable SMB1 globally but require complex passwords for the appliance account.
  3. C. Re-enable SMB1 only on every file server the appliance might access.
  4. D. Disable SMB signing so the appliance can negotiate the older protocol more easily.

Correct answer

Upgrade the appliance to the supported SMB3 firmware and keep SMB1 disabled on the file servers.

Objective/domain: Scanning and exploitation

Source: SMB security hardening in Windows Server and Windows Client

Question 5 A SOC uses an LLM to summarize malware evidence that may contain customer secrets. Which architecture best reduces data-governance risk while retaining analytical value?

Answer choices

  1. A. Send full raw evidence to any public model because model output is only a summary.
  2. B. Disable logging so sensitive prompts cannot appear in audit records.
  3. C. Give the LLM direct access to all incident repositories so it can decide what data it needs.
  4. D. Minimize or redact sensitive input to what is necessary, use an approved controlled model/service, restrict access, log usage, and retain human validation of outputs.

Correct answer

Minimize or redact sensitive input to what is necessary, use an approved controlled model/service, restrict access, log usage, and retain human validation of outputs.

Question 6 An analyst finds `ncat -l -k 4444` running under an unusual service account. Which behavior is most consistent with those options?

Answer choices

  1. A. Ncat is listening on port 4444 and is configured to keep accepting additional connections instead of exiting after the first one.
  2. B. Ncat is sending UDP packets to port 4444 because `-k` selects datagram mode as the first technical action.
  3. C. Ncat is scanning remote port 4444 repeatedly until it finds an open host.
  4. D. Ncat is verifying a TLS certificate on port 4444 because listen mode implies SSL.

Correct answer

Ncat is listening on port 4444 and is configured to keep accepting additional connections instead of exiting after the first one.

Objective/domain: Scanning and exploitation

Source: Ncat Users Guide

Question 7 An analyst sees a PowerShell command and immediately labels it “Defense Evasion.” What additional reasoning is required for a defensible ATT&CK mapping?

Answer choices

  1. A. PowerShell commands are always Persistence because scripts can survive reboot.
  2. B. PowerShell should be mapped as RDP whenever the command was launched remotely.
  3. C. Map the observed interpreter to T1059.001, then separately map any evasion behavior only if the command’s actions provide evidence of an evasion technique.
  4. D. Any encoded PowerShell is automatically the Defense Evasion tactic and no additional mapping is needed.

Correct answer

Map the observed interpreter to T1059.001, then separately map any evasion behavior only if the command’s actions provide evidence of an evasion technique.

Objective/domain: Post-exploitation and AI

Source: MITRE ATT&CK T1059.001: Command and Scripting Interpreter — PowerShell

Question 8 An endpoint is actively beaconing, and memory-resident malware is suspected. The system is already network-isolated but remains powered on. Which evidence should be prioritized before a reboot if the goal is to preserve volatile behavior?

Answer choices

  1. A. Capture volatile memory and current process/network state before performing recovery actions that would destroy that state.
  2. B. Reboot immediately to force the malware out of memory, then capture memory.
  3. C. Run a disk defragmentation pass so the forensic image is easier to analyze.
  4. D. Disable logging to prevent the malware from generating additional noise.

Correct answer

Capture volatile memory and current process/network state before performing recovery actions that would destroy that state.

Question 9 A new password verifier currently requires 12 characters, one uppercase, one lowercase, one number, one symbol, and a mandatory 60-day change. It does not check chosen passwords against known breached values. Which redesign is most consistent with current NIST guidance?

Answer choices

  1. A. Emphasize sufficient length, reject commonly used or compromised passwords with a blocklist, and remove arbitrary composition and periodic-change requirements absent evidence of compromise.
  2. B. Keep the composition rules and shorten rotation to 30 days so stolen passwords expire faster.
  3. C. Remove minimum length because a breach-password blocklist makes password length irrelevant.
  4. D. Require security questions for every password change so users can recover complex passwords.

Correct answer

Emphasize sufficient length, reject commonly used or compromised passwords with a blocklist, and remove arbitrary composition and periodic-change requirements absent evidence of compromise.

Objective/domain: Credential and cloud attacks

Source: NIST SP 800-63B-4: Authentication and Authenticator Management

Question 10 A mobile client sends `{"accountId":"A-9007","amount":250}` to `/transfer`. Changing `accountId` to another customer’s value causes the transfer to debit that customer. The server validates authentication but not ownership of `accountId`. Which control is required?

Answer choices

  1. A. Hash the `accountId` in the mobile app so users cannot read it.
  2. B. Move the account ID from the JSON body to a custom HTTP header.
  3. C. Require TLS 1.3; encrypted transport prevents object-level authorization failures.
  4. D. Authorize the authenticated principal against the referenced account object before executing the transfer.

Correct answer

Authorize the authenticated principal against the referenced account object before executing the transfer.

Objective/domain: Web and API attacks

Source: OWASP API Security Top 10 2023: API1 Broken Object Level Authorization

Where to go after the daily web set

How are GIAC GCIH questions generated?

dotCreds builds GIAC GCIH practice questions from public exam objectives and GIAC exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start GIAC GCIH practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.