Precise GIAC GCIH Free Draindumps Online
Proper study guides for Down to date GIAC GIAC Certified Incident Handler certified begins with GIAC GCIH preparation products which designed to deliver the Vivid GCIH questions by making you pass the GCIH test at your first time. Try the free GCIH demo right now.
GIAC GCIH Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
Which of the following is designed to protect the Internet resolvers (clients) from forged DNS data created by DNS cache poisoning?
- A. Stub resolver
- B. BINDER
- C. Split-horizon DNS
- D. Domain Name System Extension (DNSSEC)
Answer: D
NEW QUESTION 2
The Klez worm is a mass-mailing worm that exploits a vulnerability to open an executable attachment even in Microsoft Outlook's preview pane. The Klez worm gathers email addresses from the entries of the default Windows Address Book (WAB). Which of the following registry values can be used to identify this worm?
- A. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
- B. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- C. HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4\Wab File Name = "file and pathname of the WAB file"
- D. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Answer: C
NEW QUESTION 3
Which of the following tools is used to download the Web pages of a Website on the local system?
- A. wget
- B. jplag
- C. Nessus
- D. Ettercap
Answer: A
NEW QUESTION 4
5.2.92:4079<-----RST/ACK----------192.5.2.110:23
Which of the following types of port scan is Adam running?
- A. ACK scan
- B. FIN scan
- C. XMAS scan
- D. Idle scan
Answer: B
NEW QUESTION 5
CORRECT TEXT
Fill in the blank with the correct numeric value.
ARP poisoning is achieved in ______ steps.
- A.
Answer: 2
NEW QUESTION 6
Which of the following can be used to perform session hijacking?
Each correct answer represents a complete solution. Choose all that apply.
- A. Cross-site scripting
- B. Session fixation
- C. ARP spoofing
- D. Session sidejacking
Answer: ABD
NEW QUESTION 7
Which of the following statements are true about a keylogger?
Each correct answer represents a complete solution. Choose all that apply.
- A. It records all keystrokes on the victim's computer in a predefined log file.
- B. It can be remotely installed on a computer system.
- C. It is a software tool used to trace all or specific activities of a user on a computer.
- D. It uses hidden code to destroy or scramble data on the hard disk.
Answer: ABC
NEW QUESTION 8
Which of the following controls is described in the statement given below?
"It ensures that the enforcement of organizational security policy does not rely on voluntary web application user compliance. It secures information by assigning sensitivity labels on information and comparing this to the level of security a user is operating at."
- A. Role-based Access Control
- B. Attribute-based Access Control
- C. Discretionary Access Control
- D. Mandatory Access Control
Answer: D
NEW QUESTION 9
Adam works as a Security Administrator for the Umbrella Inc. A project has been assigned to him to strengthen the security policies of the company, including its password policies. However, due to some old applications, Adam is only able to enforce a password group policy in Active Directory with a minimum of 10 characters. He informed the employees of the company, that the new password policy requires that everyone must have complex passwords with at least 14 characters. Adam wants to ensure that everyone is using complex passwords that meet the new security policy requirements. He logged on to one of the network's domain controllers and runs the following command:
Which of the following actions will this command take?
- A. Dumps the SAM password hashes to pwd.txt
- B. Dumps the SAM password file to pwd.txt
- C. Dumps the Active Directory password hashes to pwd.txt
- D. The password history file is transferred to pwd.txt
Answer: A
NEW QUESTION 10
In which of the following methods does an hacker use packet sniffing to read network traffic between two parties to steal the session cookies?
- A. Cross-site scripting
- B. Physical accessing
- C. Session fixation
- D. Session sidejacking
Answer: D
NEW QUESTION 11
Which of the following characters will you use to check whether an application is vulnerable to an SQL injection attack?
- A. Dash (-)
- B. Double quote (")
- C. Single quote (')
- D. Semi colon (;)
Answer: C
NEW QUESTION 12
You run the following command while using Nikto Web scanner:
perl nikto.pl -h 192.168.0.1 -p 443
What action do you want to perform?
- A. Using it as a proxy server
- B. Updating Nikto
- C. Seting Nikto for network sniffing
- D. Port scanning
Answer: D
NEW QUESTION 13
Rick works as a Computer Forensic Investigator for BlueWells Inc. He has been informed that some confidential information is being leaked out by an employee of the company. Rick suspects that someone is sending the information through email. He checks the emails sent by some employees to other networks. Rick finds out that Sam, an employee of the Sales department, is continuously sending text files that contain special symbols, graphics, and signs. Rick suspects that Sam is using the Steganography technique to send data in a disguised form. Which of the following techniques is Sam using?
Each correct answer represents a part of the solution. Choose all that apply.
- A. Linguistic steganography
- B. Perceptual masking
- C. Technical steganography
- D. Text Semagrams
Answer: AD
NEW QUESTION 14
Windump is a Windows port of the famous TCPDump packet sniffer available on a variety of platforms. In order to use this tool on the Windows platform a user must install a packet capture library.
What is the name of this library?
- A. PCAP
- B. SysPCap
- C. WinPCap
- D. libpcap
Answer: C
NEW QUESTION 15
Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of the incident response team. As a demo project he asked members of the incident response team to perform the following actions:
Remove the network cable wires.
Isolate the system on a separate VLAN
Use a firewall or access lists to prevent communication into or out of the system.
Change DNS entries to direct traffic away from compromised system
Which of the following steps of the incident handling process includes the above actions?
- A. Identification
- B. Containment
- C. Eradication
- D. Recovery
Answer: B
NEW QUESTION 16
You want to integrate the Nikto tool with nessus vulnerability scanner. Which of the following steps will you take to accomplish the task?
Each correct answer represents a complete solution. Choose two.
- A. Place nikto.pl file in the /etc/nessus directory.
- B. Place nikto.pl file in the /var/www directory.
- C. Place the directory containing nikto.pl in root's PATH environment variable.
- D. Restart nessusd service.
Answer: CD
NEW QUESTION 17
......
Thanks for reading the newest GCIH exam dumps! We recommend you to try the PREMIUM Downloadfreepdf.net GCIH dumps in VCE and PDF here: https://www.downloadfreepdf.net/GCIH-pdf-download.html (328 Q&As Dumps)