Regenerate GIAC Certified Incident Handler GCIH Free Exam
Exam Code: GCIH (Practice Exam Latest Test Questions VCE PDF)
Exam Name: GIAC Certified Incident Handler
Certification Provider: GIAC
Free Today! Guaranteed Training- Pass GCIH Exam.
GIAC GCIH Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
Ryan, a malicious hacker submits Cross-Site Scripting (XSS) exploit code to the Website of Internet forum for online discussion. When a user visits the infected Web page, code gets automatically executed and Ryan can easily perform acts like account hijacking, history theft etc. Which of the following types of Cross-Site Scripting attack Ryan intends to do?
- A. Non persistent
- B. Document Object Model (DOM)
- C. SAX
- D. Persistent
Answer: D
NEW QUESTION 2
Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?
- A. Whishker
- B. Nessus
- C. SARA
- D. Nmap
Answer: B
NEW QUESTION 3
Adam works as a Security Analyst for Umbrella Inc. CEO of the company ordered him to implement two-factor authentication for the employees to access their networks. He has told him that he would like to use some type of hardware device in tandem with a security or identifying pin number. Adam decides to implement smart cards but they are not cost effective.
Which of the following types of hardware devices will Adam use to implement two-factor authentication?
- A. Biometric device
- B. Security token
- C. Proximity cards
- D. One Time Password
Answer: B
NEW QUESTION 4
Sharpening, Rotating, Resampling, and Softening the image.
Which of the following Steganography attacks is Victor using?
- A. Stegdetect Attack
- B. Chosen-Stego Attack
- C. Steg-Only Attack
- D. Active Attacks
Answer: D
NEW QUESTION 5
Which of the following are based on malicious code?
Each correct answer represents a complete solution. Choose two.
- A. Denial-of-Service (DoS)
- B. Biometrics
- C. Trojan horse
- D. Worm
Answer: CD
NEW QUESTION 6
Which of the following is a version of netcat with integrated transport encryption capabilities?
- A. Encat
- B. Nikto
- C. Socat
- D. Cryptcat
Answer: D
NEW QUESTION 7
A Denial-of-Service (DoS) attack is mounted with the objective of causing a negative impact on the performance of a computer or network. It is also known as network saturation attack or bandwidth consumption attack. Attackers perform DoS attacks by sending a large number of protocol packets to a network. The problems caused by a DoS attack are as follows:
l Saturation of network resources
l Disruption of connections between two computers, thereby preventing communications between services
l Disruption of services to a specific computer
l Failure to access a Web site
l Increase in the amount of spam
Which of the following can be used as countermeasures against DoS attacks?
Each correct answer represents a complete solution. Choose all that apply.
- A. Blocking undesired IP addresses
- B. Applying router filtering
- C. Disabling unneeded network services
- D. Permitting network access only to desired traffic
Answer: ABCD
NEW QUESTION 8
Adam, a novice web user, is very conscious about the security. He wants to visit the Web site that is known to have malicious applets and code. Adam always makes use of a basic Web Browser to perform such testing.
Which of the following web browsers can adequately fill this purpose?
- A. Mozilla Firefox
- B. Internet explorer
- C. Lynx
- D. Safari
Answer: C
NEW QUESTION 9
John, a part-time hacker, has accessed in unauthorized way to the www.yourbank.com banking Website and stolen the bank account information of its users and their credit card numbers by using the SQL injection attack. Now, John wants to sell this information to malicious person Mark and make a deal to get a good amount of money. Since, he does not want to send the hacked information in the clear text format to Mark; he decides to send information in hidden text. For this, he takes a steganography tool and hides the information in ASCII text by appending whitespace to the end of lines and encrypts the hidden information by using the IDEA encryption algorithm. Which of the following tools is John using for steganography?
- A. Image Hide
- B. 2Mosaic
- C. Snow.exe
- D. Netcat
Answer: C
NEW QUESTION 10
Which of the following types of scan does not open a full TCP connection?
- A. FIN scan
- B. ACK scan
- C. Stealth scan
- D. Idle scan
Answer: C
NEW QUESTION 11
Adam works as a Network administrator for Umbrella Inc. He noticed that an ICMP ECHO requests is coming from some suspected outside sources. Adam suspects that some malicious hacker is trying to perform ping sweep attack on the network of the company. To stop this malicious activity, Adam blocks the ICMP ECHO request from any outside sources.
What will be the effect of the action taken by Adam?
- A. Network turns completely immune from the ping sweep attacks.
- B. Network is still vulnerable to ping sweep attack.
- C. Network is protected from the ping sweep attack until the next reboot of the server.
- D. Network is now vulnerable to Ping of death attack.
Answer: B
NEW QUESTION 12
Your friend plans to install a Trojan on your computer. He knows that if he gives you a new version of chess.exe, you will definitely install the game on your computer. He picks up a Trojan and joins it with chess.exe. Which of the following tools are required in such a scenario?
Each correct answer represents a part of the solution. Choose three.
- A. NetBus
- B. Absinthe
- C. Yet Another Binder
- D. Chess.exe
Answer: ACD
NEW QUESTION 13
Which of the following statements are correct about spoofing and session hijacking?
Each correct answer represents a complete solution. Choose all that apply.
- A. Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target and the valid user cannot be active.
- B. Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target but the valid user can be active.
- C. Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is disconnected.
- D. Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is not disconnected.
Answer: BD
NEW QUESTION 14
Which of the following incident response team members ensures that the policies of the organization are enforced during the incident response?
- A. Information Security representative
- B. Legal representative
- C. Human Resource
- D. Technical representative
Answer: C
NEW QUESTION 15
You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But since few days, it is identified that this process is providing a way to spammers to perform different types of e-mail attacks. Which of the following phases of the Incident handling process will now be involved in resolving this process and find a solution?
Each correct answer represents a part of the solution. Choose all that apply.
- A. Eradication
- B. Contamination
- C. Preparation
- D. Recovery
- E. Identification
Answer: ABD
NEW QUESTION 16
Victor works as a professional Ethical Hacker for SecureEnet Inc. He wants to scan the wireless network of the company. He uses a tool that is a free open-source utility for network exploration. The tool uses raw IP packets to determine the following:
What ports are open on our network systems.
What hosts are available on the network.
Identify unauthorized wireless access points.
What services (application name and version) those hosts are offering.
What operating systems (and OS versions) they are running.
What type of packet filters/firewalls are in use.
Which of the following tools is Victor using?
- A. Nessus
- B. Kismet
- C. Nmap
- D. Sniffer
Answer: C
NEW QUESTION 17
......
Recommend!! Get the Full GCIH dumps in VCE and PDF From Dumps-files.com, Welcome to Download: https://www.dumps-files.com/files/GCIH/ (New 328 Q&As Version)