Top Tips Of Rebirth GCIH Testing Material

Cause all that matters here is passing the GIAC GCIH exam. Cause all that you need is a high score of GCIH GIAC Certified Incident Handler exam. The only one thing you need to do is downloading Exambible GCIH exam study guides now. We will not let you down with our money-back guarantee.

Also have GCIH free dumps questions for you:

NEW QUESTION 1
CORRECT TEXT
Fill in the blank with the appropriate option to complete the statement below.
You want to block all UDP packets coming to the Linux server using the portsentry utility. For this, you have to enable the ______ option in the portsentry configuration file.

  • A.

Answer: BLOCK_UDP

NEW QUESTION 2
Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason.
Which of the following mistakes made by Jason helped the Forensic Investigators catch him?

  • A. Jason did not perform a vulnerability assessment.
  • B. Jason did not perform OS fingerprinting.
  • C. Jason did not perform foot printing.
  • D. Jason did not perform covering tracks.
  • E. Jason did not perform port scanning.

Answer: D

NEW QUESTION 3
In which of the following attacks does an attacker spoof the source address in IP packets that are sent to the victim?

  • A. Dos
  • B. DDoS
  • C. Backscatter
  • D. SQL injection

Answer: C

NEW QUESTION 4
Which of the following tools is used for port scanning?

  • A. NSLOOKUP
  • B. NETSH
  • C. Nmap
  • D. L0phtcrack

Answer: C

NEW QUESTION 5
Which of the following commands is used to access Windows resources from Linux workstation?

  • A. mutt
  • B. scp
  • C. rsync
  • D. smbclient

Answer: D

NEW QUESTION 6
Adam works as an Incident Handler for Umbrella Inc. His recent actions towards the incident are not up to the standard norms of the company. He always forgets some steps and procedures while handling responses as they are very hectic to perform.
Which of the following steps should Adam take to overcome this problem with the least administrative effort?

  • A. Create incident manual read it every time incident occurs.
  • B. Appoint someone else to check the procedures.
  • C. Create incident checklists.
  • D. Create new sub-team to keep check.

Answer: C

NEW QUESTION 7
When you conduct the XMAS scanning using Nmap, you find that most of the ports scanned do not give a response. What can be the state of these ports?

  • A. Filtered
  • B. Open
  • C. Closed

Answer: B

NEW QUESTION 8
Which of the following viruses/worms uses the buffer overflow attack?

  • A. Chernobyl (CIH) virus
  • B. Nimda virus
  • C. Klez worm
  • D. Code red worm

Answer: D

NEW QUESTION 9
Adam, a malicious hacker, wants to perform a reliable scan against a remote target. He is not concerned about being stealth at this point.
Which of the following type of scans would be most accurate and reliable?

  • A. UDP sacn
  • B. TCP Connect scan
  • C. ACK scan
  • D. Fin scan

Answer: B

NEW QUESTION 10
Which of the following HTTP requests is the SQL injection attack?

  • A. http://www.xsecurity.com/cgiin/bad.cgi?foo=..%fc%80%80%80%80%af../bin/ls%20-al
  • B. http://www.victim.com/example?accountnumber=67891&creditamount=999999999
  • C. http://www.myserver.com/search.asp?lname=adam%27%3bupdate%20usertable%20set% 20pass wd%3d %27hCx0r%27%3b--%00
  • D. http://www.myserver.com/script.php?mydata=%3cscript%20src=%22http%3a%2f% 2fwww.yourser ver.c0m %2fbadscript.js%22%3e%3c%2fscript%3e

Answer: C

NEW QUESTION 11
Which of the following attacking methods allows the bypassing of access control lists on servers or routers, either hiding a computer on a network or allowing it to impersonate another computer by changing the Media Access Control address?

  • A. IP address spoofing
  • B. VLAN hoping
  • C. ARP spoofing
  • D. MAC spoofing

Answer: D

NEW QUESTION 12
Which of the following netcat parameters makes netcat a listener that automatically restarts itself when a connection is dropped?

  • A. -u
  • B. -l
  • C. -p
  • D. -L

Answer: D

NEW QUESTION 13
Which of the following strategies allows a user to limit access according to unique hardware information supplied by a potential client?

  • A. Extensible Authentication Protocol (EAP)
  • B. WEP
  • C. MAC address filtering
  • D. Wireless Transport Layer Security (WTLS)

Answer: C

NEW QUESTION 14
US Garments wants all encrypted data communication between corporate office and remote location.
They want to achieve following results:
l Authentication of users
l Anti-replay
l Anti-spoofing
l IP packet encryption
They implemented IPSec using Authentication Headers (AHs). Which results does this solution provide? (Click the Exhibit button on the toolbar to see the case study.)
Each correct answer represents a complete solution. Choose all that apply.

  • A. Anti-replay
  • B. IP packet encryption
  • C. Authentication of users
  • D. Anti-spoofing

Answer: AD

NEW QUESTION 15
Which of the following applications is an example of a data-sending Trojan?

  • A. SubSeven
  • B. Senna Spy Generator
  • C. Firekiller 2000
  • D. eBlaster

Answer: D

NEW QUESTION 16
Which of the following would allow you to automatically close connections or restart a server or service when a DoS attack is detected?

  • A. Signature-based IDS
  • B. Network-based IDS
  • C. Passive IDS
  • D. Active IDS

Answer: D

NEW QUESTION 17
......

P.S. Thedumpscentre.com now are offering 100% pass ensure GCIH dumps! All GCIH exam questions have been updated with correct answers: https://www.thedumpscentre.com/GCIH-dumps/ (328 New Questions)