GIAC · Certified Incident Handler GCIH

GIAC Certified Incident Handler GCIH Exam Practice Questions

842 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 842 questions in this pack

Question 1

Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of the incident response team. As a demo project he asked members of the incident response team to perform the following actions: • Remove the network cable wires. • Isolate the system on a separate VLAN • Use a firewall or access lists to prevent communication into or out of the system. • Change DNS entries to direct traffic away from compromised system Which of the following steps of the incident handling process includes the above actions?

  1. Identification
  2. Containment
  3. Eradication
  4. Recovery
Show answer and explanation

Correct answer: B. Containment

All four actions listed, removing network cables, isolating on a VLAN, using firewalls/access lists, and changing DNS entries, are classic containment measures designed to limit the scope and impact of a security incident. Containment is the phase where responders take steps to stop the attack from spreading and prevent further damage, while preserving evidence. Identification focuses on detecting the incident, eradication removes the threat, and recovery restores systems to normal operation.

Why the other options are wrong

  • A. Identification is the detection and confirmation of a security incident, not the implementation of isolation measures.
  • C. Eradication removes the attacker's tools and access, but the listed actions are preventative controls rather than removal steps.
  • D. Recovery restores systems to normal operation after the threat is eliminated; it does not involve isolation or access prevention.

Question 2

Adam, a novice computer user, works primarily from home as a medical professional. He just bought a brand new Dual Core Pentium computer with over 3 GB of RAM. After about two months of working on his new computer, he notices that it is not running nearly as fast as it used to. Adam uses antivirus software, anti-spyware software, and keeps the computer up-to-date with Microsoft patches. After another month of working on the computer, Adam finds that his computer is even more noticeably slow. He also notices a window or two pop-up on his screen, but they quickly disappear. He has seen these windows show up, even when he has not been on the Internet. Adam notices that his computer only has about 10 GB of free space available. Since his hard drive is a 200 GB hard drive, Adam thinks this is very odd. Which of the following is the mostly likely the cause of the problem?

  1. Computer is infected with the stealth kernel level rootkit.
  2. Computer is infected with stealth virus.
  3. Computer is infected with the Stealth Trojan Virus.
  4. Computer is infected with the Self-Replication Worm.
Show answer and explanation

Correct answer: A. Computer is infected with the stealth kernel level rootkit.

rootkit. A stealth kernel-level rootkit runs at the deepest level of the operating system and controls what the OS reports, so it can hide files, processes, and disk consumption from antivirus and anti-spyware tools. That matches the symptoms exactly: a patched, protected machine that steadily slows down, shows pop-ups that appear and vanish even when offline, and loses roughly 190 GB of disk space while the security software reports nothing. Hidden resource consumption combined with clean scans is the classic signature of a kernel-level rootkit.

Why the other options are wrong

  • B. A stealth virus hides changes to the files it infects, but it spreads through host files rather than concealing an entire OS-level footprint and massive disk use.
  • C. Trojan programs rely on tricking the user into running them and do not subvert the kernel to conceal hidden resource consumption.
  • D. A worm spreads copies across networks and shares, generating traffic and files that installed antivirus software would very likely flag.

Question 3

Which of the following types of attacks is only intended to make a computer resource unavailable to its users?

  1. Denial of Service attack
  2. Replay attack
  3. Teardrop attack
  4. Land attack
Show answer and explanation

Correct answer: A. Denial of Service attack

A Denial of Service (DoS) attack is specifically designed and intended solely to make a resource unavailable to legitimate users by overwhelming it with traffic or exploiting vulnerabilities to crash the service. The defining characteristic of a DoS attack is that its only goal is availability disruption, not data theft, authentication bypass, or other objectives.

Why the other options are wrong

  • B. A replay attack involves capturing and resending valid data to impersonate a user or gain unauthorized access, not merely denying availability.
  • C. A teardrop attack is a specific DoS technique that sends fragmented packets, but it is a type of DoS rather than the category that encompasses only availability attacks.
  • D. A land attack sends spoofed packets with the target's own IP as both source and destination, designed to crash the system, but is a specific DoS variant rather than the general category.

See all 10 free questions Get the full pack, US$39

842 practice questions for GIAC Certified Incident Handler (GCIH), with full explanations.

Every question comes with the correct answer and a clear explanation. Mapped to the current GCIH exam objectives.

  • 842 questions mapped to the GCIH exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The GCIH costs US$999 per attempt. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 842 questions

What makes the GCIH hard

The GCIH covers the full incident response lifecycle from both sides of the attack. It is 106 questions in four hours, open book, with a 69% pass mark.

The exam tests how attackers operate and how defenders respond: reconnaissance, exploitation, privilege escalation and lateral movement on one side, and detection, containment, eradication and recovery on the other. Candidates who know incident response but have not studied attacker techniques consistently get caught out.

This pack has 842 practice questions, matching how much ground the GCIH covers, so it is a way to find the gaps before GIAC does.

About the exam

The GCIH validates hands-on skill in detecting, responding to, and recovering from security incidents. It covers attacker tactics and techniques alongside the defensive workflows needed to handle them, making it one of the most practical blue team certifications available. It is aligned to SANS SEC504 (Hacker Techniques, Incident Handling, and Offensive Counter-Measures) and mapped to DoD 8140.

Exam topics

  • Incident handling process: preparation, identification, containment, eradication, recovery
  • Attacker techniques: reconnaissance, scanning, exploitation, privilege escalation
  • Network intrusion analysis: detecting and investigating network-based attacks
  • Malware analysis: identifying and handling malicious code
  • Web application attacks: SQL injection, XSS, and application-layer exploitation
  • Insider threats: detecting and responding to internal incidents
  • Hacker tools: understanding and defending against common attacker toolsets

106 questions, 4 hours, passing score 69%, open book, US$999 per attempt, valid 4 years, maps to DoD 8140.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Certified Incident Handler GCIH pack?

842 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.