[2022] Use Valid GCIH Exam - Actual Exam Question & Answer
Test Engine to Practice GCIH Test Questions
Topics Tested in GIAC GCIH Validation
The candidates who want to get the minimum passing score in the GCIH exam will need to demonstrate that they are proficient in the following topics:
- Understanding how to defend against attacks and mitigate each situation to gather evidence and identify the sources;
- Developing the necessary steps for developing professional digital investigations and working with different types of network data;
- Finding out about different techniques related to open and public source reconnaissance and knowing how to defend against them;
- Identifying and mitigating against any attacks that might affect the physical access into the network;
- Becoming able to proficiently handle any incident and understanding how the PICERL incident management process works;
- Accelerating solid knowledge of the three methods used for preventing password cracking;
- Becoming able to identify and mitigate against the Metasploit use;
- Discerning how to defend against attacks that might appear on the network;
- Defending against drive-by attacks when working with modern software environments;
- Understanding how to mitigate and defend against Netcat or other convert tools;
- Scanning and mitigating reconnaissance of different types of SMB services.
- Mitigating against attacks against the Web Application and defending against such threats;
- Identifying any attacks on the Domain and defending against them when operating a Windows environment;
GCIH Certification Path
There are no prerequisites
NEW QUESTION 75
When you conduct the XMAS scanning using Nmap, you find that most of the ports scanned do not give a response. What can be the state of these ports?
- A. Filtered
- B. Open
- C. Closed
Answer: B
Explanation:
Section: Volume C
Explanation
NEW QUESTION 76
You work as a System Engineer for Cyber World Inc. Your company has a single Active Directory domain. All servers in the domain run Windows Server 2008. The Microsoft Hyper-V server role has been installed on one of the servers, namely uC1. uC1 hosts twelve virtual machines. You have been given the task to configure the Shutdown option for uC1, so that each virtual machine shuts down before the main Hyper-V server shuts down. Which of the following actions will you perform to accomplish the task?
- A. Manually shut down each of the guest operating systems before the server shuts down.
- B. Create a logon script to shut down the guest operating system before the server shuts down.
- C. Enable the Shut Down the Guest Operating System option in the Automatic Stop Action Properties on each virtual machine.
- D. Create a batch file to shut down the guest operating system before the server shuts down.
Answer: C
NEW QUESTION 77
In which of the following attacks does an attacker spoof the source address in IP packets that are sent to the victim?
- A. Backscatter
- B. DDoS
- C. SQL injection
- D. Dos
Answer: A
NEW QUESTION 78
Which of the following is a version of netcat with integrated transport encryption capabilities?
- A. Cryptcat
- B. Encat
- C. Nikto
- D. Socat
Answer: A
NEW QUESTION 79
Which of the following wireless network security solutions refers to an authentication process in which a user can connect wireless access points to a centralized server to ensure that all hosts are properly authenticated?
- A. Wired Equivalent Privacy (WEP)
- B. IEEE 802.1x
- C. Remote Authentication Dial-In User Service (RADIUS)
- D. Wi-Fi Protected Access 2 (WPA2)
Answer: B
NEW QUESTION 80
Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason.
Which of the following mistakes made by Jason helped the Forensic Investigators catch him?
- A. Jason did not perform covering tracks.
- B. Jason did not perform OS fingerprinting.
- C. Jason did not perform port scanning.
- D. Jason did not perform foot printing.
- E. Jason did not perform a vulnerability assessment.
Answer: A
NEW QUESTION 81
Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of the incident response team. As a demo project he asked members of the incident response team to perform the following actions:
Remove the network cable wires.
Isolate the system on a separate VLAN
Use a firewall or access lists to prevent communication into or out of the system.
Change DNS entries to direct traffic away from compromised system
Which of the following steps of the incident handling process includes the above actions?
- A. Identification
- B. Recovery
- C. Eradication
- D. Containment
Answer: D
NEW QUESTION 82
Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable information regarding the operating system and applications running on the systems?
- A. Attack phase
- B. Post-attack phase
- C. On-attack phase
- D. Pre-attack phase
Answer: D
Explanation:
Section: Volume C
NEW QUESTION 83
Which of the following Denial-of-Service (DoS) attacks employ IP fragmentation mechanism?
Each correct answer represents a complete solution. Choose two.
- A. SYN flood attack
- B. Land attack
- C. Ping of Death attack
- D. Teardrop attack
Answer: C,D
NEW QUESTION 84
Brutus is a password cracking tool that can be used to crack the following authentications:
* HTTP (Basic Authentication)
* HTTP (HTML Form/CGI)
* POP3 (Post Office Protocol v3)
* FTP (File Transfer Protocol)
* SMB (Server Message Block)
* Telnet
Which of the following attacks can be performed by Brutus for password cracking?
Each correct answer represents a complete solution. Choose all that apply.
- A. Hybrid attack
- B. Brute force attack
- C. Dictionary attack
- D. Man-in-the-middle attack
- E. Replay attack
Answer: A,B,C
NEW QUESTION 85
Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of
the incident response team. As a demo project he asked members of the incident response team to perform the
following actions:
Remove the network cable wires.
Isolate the system on a separate VLAN.
Use a firewall or access lists to prevent communication into or out of the system.
Change DNS entries to direct traffic away from compromised system.
Which of the following steps of the incident handling process includes the above actions?
- A. Identification
- B. Recovery
- C. Eradication
- D. Containment
Answer: D
NEW QUESTION 86
James works as a Database Administrator for Techsoft Inc. The company has a SQL Server 2005 computer.
The computer has a database named Sales. Users complain that the performance of the database has deteriorated. James opens the System Monitor tool and finds that there is an increase in network traffic. What kind of attack might be the cause of the performance deterioration?
- A. Internal attack
- B. Denial-of-Service
- C. Virus
- D. Injection
Answer: B
Explanation:
Section: Volume B
NEW QUESTION 87
John works as a Network Security Professional. He is assigned a project to test the security of
www.we-are-secure.com. He establishes a connection to a target host running a Web service with netcat and sends a
bad html request in order to retrieve information about the service on the host.
Which of the following attacks is John using?
- A. Eavesdropping
- B. Banner grabbing
- C. War driving
- D. Sniffing
Answer: B
NEW QUESTION 88
Which of the following is the best method of accurately identifying the services running on a victim host?
- A. Use of a port scanner to scan each port to confirm the services running.
- B. Use of the manual method of telnet to each of the open ports.
- C. Use of hit and trial method to guess the services and ports of the victim host.
- D. Use of a vulnerability scanner to try to probe each port to verify which service is running.
Answer: B
NEW QUESTION 89
You work as a System Engineer for Cyber World Inc. Your company has a single Active Directory domain. All servers in
the domain run Windows Server 2008. The Microsoft Hyper-V server role has been installed on one of the servers,
namely uC1. uC1 hosts twelve virtual machines. You have been given the task to configure the Shutdown option for
uC1, so that each virtual machine shuts down before the main Hyper-V server shuts down. Which of the following
actions will you perform to accomplish the task?
- A. Enable the Shut Down the Guest Operating System option in the Automatic Stop Action Properties on each virtual
machine. - B. Manually shut down each of the guest operating systems before the server shuts down.
- C. Create a logon script to shut down the guest operating system before the server shuts down.
- D. Create a batch file to shut down the guest operating system before the server shuts down.
Answer: A
NEW QUESTION 90
Which of the following functions in c/c++ can be the cause of buffer overflow?
Each correct answer represents a complete solution. Choose two.
- A. printf()
- B. strcat()
- C. strcpy()
- D. strlength()
Answer: B,C
NEW QUESTION 91
Which of the following attacks come under the category of layer 2 Denial-of-Service attacks?
Each correct answer represents a complete solution. Choose all that apply.
- A. RF jamming attack
- B. Spoofing attack
- C. Password cracking
- D. SYN flood attack
Answer: B,D
Explanation:
Section: Volume A
NEW QUESTION 92
Which of the following types of malware does not replicate itself but can spread only when the circumstances are beneficial?
- A. Blended threat
- B. Worm
- C. Trojan horse
- D. Mass mailer
Answer: C
Explanation:
Section: Volume B
NEW QUESTION 93
......
GCIH Actual Questions Answers PDF 100% Cover Real Exam Questions: https://www.dumps4pdf.com/GCIH-valid-braindumps.html
GCIH Real Exam Questions Test Engine Dumps Training With 335 Questions: https://drive.google.com/open?id=1jrOCL0RCn0MGCh2hl39F1UDUPbCqCChS