How Many Questions Of GCIH Free Practice Test

Proper study guides for Improve GIAC GIAC Certified Incident Handler certified begins with GIAC GCIH preparation products which designed to deliver the Validated GCIH questions by making you pass the GCIH test at your first time. Try the free GCIH demo right now.

Free GCIH Demo Online For GIAC Certifitcation:

NEW QUESTION 1
5.2.92:4079 ---------FIN--------->192.5.2.110:23


Solution:


Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 2
You work as a Network Penetration tester in the Secure Inc. Your company takes the projects to test the security of various companies. Recently, Secure Inc. has assigned you a project to test the security of a Web site. You go to the Web site login page and you run the following SQL query:
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = 'attacker@somehwere.com'; DROP TABLE members; --'
What task will the above SQL query perform?

  • A. Deletes the database in which members table resides.
  • B. Deletes the rows of members table where email id is 'attacker@somehwere.com' given.
  • C. Performs the XSS attacks.
  • D. Deletes the entire members table.

Answer: D

NEW QUESTION 3
Victor wants to send an encrypted message to his friend. He is using certain steganography technique to accomplish this task. He takes a cover object and changes it accordingly to hide information. This secret information is recovered only when the algorithm compares the changed cover with the original cover.
Which of the following Steganography methods is Victor using to accomplish the task?

  • A. The distortion technique
  • B. The spread spectrum technique
  • C. The substitution technique
  • D. The cover generation technique

Answer: A

NEW QUESTION 4
The IT administrator wants to implement a stronger security policy. What are the four most important security priorities for Exambible Software Systems Pvt. Ltd.? (Click the Exhibit button on the toolbar to see the case study.)

  • A. Providing secure communications between the overseas office and the headquarters.
  • B. Implementing Certificate services on Texas office.
  • C. Protecting employee data on portable computers.
  • D. Providing two-factor authentication.
  • E. Ensuring secure authentication.
  • F. Preventing unauthorized network access.
  • G. Providing secure communications between Washington and the headquarters office.
  • H. Preventing denial-of-service attacks.

Answer: ACEF

NEW QUESTION 5
Maria works as a professional Ethical Hacker. She recently got a project to test the security of www.we-are-secure.com. Arrange the three pre -test phases of the attack to test the security of weare-secure.
GCIH dumps exhibit


Solution:
GCIH dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 6
Which of the following tools can be used for network sniffing as well as for intercepting conversations through session hijacking?

  • A. Ethercap
  • B. Tripwire
  • C. IPChains
  • D. Hunt

Answer: D

NEW QUESTION 7
Victor works as a professional Ethical Hacker for SecureEnet Inc. He has been assigned a job to test an image, in which some secret information is hidden, using Steganography. Victor performs the following techniques to accomplish the task:


Solution:


Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 8
Which of the following tools can be used as penetration tools in the Information system auditing process?
Each correct answer represents a complete solution. Choose two.

  • A. Nmap
  • B. Snort
  • C. SARA
  • D. Nessus

Answer: CD

NEW QUESTION 9
You have configured a virtualized Internet browser on your Windows XP professional computer. Using the virtualized Internet browser, you can protect your operating system from which of the following?

  • A. Brute force attack
  • B. Mail bombing
  • C. Distributed denial of service (DDOS) attack
  • D. Malware installation from unknown Web sites

Answer: D

NEW QUESTION 10
You work as a Network Administrator for InformSec Inc. You find that the TCP port number 23476 is open on your server. You suspect that there may be a Trojan named Donald Dick installed on your server. Now you want to verify whether Donald Dick is installed on it or not. For this, you want to know the process running on port 23476, as well as the process id, process name, and the path of the process on your server. Which of the following applications will you most likely use to accomplish the task?

  • A. Tripwire
  • B. SubSeven
  • C. Netstat
  • D. Fport

Answer: D

NEW QUESTION 11
Which of the following statements is true about the difference between worms and Trojan horses?

  • A. Trojan horses are a form of malicious codes while worms are not.
  • B. Trojan horses are harmful to computers while worms are not.
  • C. Worms can be distributed through emails while Trojan horses cannot.
  • D. Worms replicate themselves while Trojan horses do not.

Answer: D

NEW QUESTION 12
Adam, a malicious hacker purposely sends fragmented ICMP packets to a remote target. The total size of this ICMP packet once reconstructed is over 65,536 bytes. On the basis of above information, which of the following types of attack is Adam attempting to perform?

  • A. Fraggle attack
  • B. Ping of death attack
  • C. SYN Flood attack
  • D. Land attack

Answer: B

NEW QUESTION 13
Peter works as a Network Administrator for the Exambible Inc. The company has a Windows- based network. All client computers run the Windows XP operating system. The employees of the company complain that suddenly all of the client computers have started working slowly. Peter finds that a malicious hacker is attempting to slow down the computers by flooding the network with a large number of requests. Which of the following attacks is being implemented by the malicious hacker?

  • A. SQL injection attack
  • B. Denial-of-Service (DoS) attack
  • C. Man-in-the-middle attack
  • D. Buffer overflow attack

Answer: B

NEW QUESTION 14
Choose the items from the given list that are required to be in the response kit of an Incident Handler.
GCIH dumps exhibit


Solution:
GCIH dumps exhibit

Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 15
John visits an online shop that stores the IDs and prices of the items to buy in a cookie. After selecting the items that he wants to buy, the attacker changes the price of the item to 1.
Original cookie values:
ItemID1=2
ItemPrice1=900
ItemID2=1
ItemPrice2=200
Modified cookie values:
ItemID1=2
ItemPrice1=1
ItemID2=1
ItemPrice2=1
Now, he clicks the Buy button, and the prices are sent to the server that calculates the total price.
Which of the following hacking techniques is John performing?

  • A. Computer-based social engineering
  • B. Man-in-the-middle attack
  • C. Cross site scripting
  • D. Cookie poisoning

Answer: D

NEW QUESTION 16
108 ms 14 0.so-4-1-0.TL1.ATL5.ALTER.NET (152.63.10.129) 37.894 ms 33.244 ms


Solution:


Does this meet the goal?
  • A. Yes
  • B. Not Mastered

Answer: A

NEW QUESTION 17
......

100% Valid and Newest Version GCIH Questions & Answers shared by Certleader, Get Full Dumps HERE: https://www.certleader.com/GCIH-dumps.html (New 328 Q&As)