[Jan-2022] GCIH Dumps are Available for Instant Access from ValidDumps
Study resources for the Valid GCIH Braindumps!
GCIH Structure
The test GCIH is the only benchmark necessary for obtaining the GIAC Certified Incident Handler designation. Also, it’s a proctored exam and candidates should pay a registration fee of $1,999 to be eligible for it. To add more, the exam includes 100 to 150 inquiries with different levels of complexity and structure. The candidates should know that they will have only 4 hours to reply to as many questions as possible and get a passing score of 70%.
NEW QUESTION 44
John works as a Network Security Professional. He is assigned a project to test the security of www.we-are-secure.com. He establishes a connection to a target host running a Web service with netcat and sends a bad html request in order to retrieve information about the service on the host.
Which of the following attacks is John using?
- A. Eavesdropping
- B. War driving
- C. Sniffing
- D. Banner grabbing
Answer: D
Explanation:
Section: Volume C
NEW QUESTION 45
In which of the following attacks does an attacker use packet sniffing to read network traffic between two parties to
steal the session cookie?
- A. Cross-site scripting
- B. ARP spoofing
- C. Session fixation
- D. Session sidejacking
Answer: D
NEW QUESTION 46
Peter works as a Network Administrator for the PassGuide Inc. The company has a Windows-based network. All client
computers run the Windows XP operating system. The employees of the company complain that suddenly all of the
client computers have started working slowly. Peter finds that a malicious hacker is attempting to slow down the
computers by flooding the network with a large number of requests. Which of the following attacks is being
implemented by the malicious hacker?
- A. Man-in-the-middle attack
- B. Buffer overflow attack
- C. Denial-of-Service (DoS) attack
- D. SQL injection attack
Answer: C
NEW QUESTION 47
Victor wants to send an encrypted message to his friend. He is using certain steganography technique to accomplish
this task. He takes a cover object and changes it accordingly to hide information. This secret information is recovered
only when the algorithm compares the changed cover with the original cover. Which of the following Steganography
methods is Victor using to accomplish the task?
- A. The substitution technique
- B. The cover generation technique
- C. The spread spectrum technique
- D. The distortion technique
Answer: D
NEW QUESTION 48
Your company has been hired to provide consultancy, development, and integration services for a company named Brainbridge International. You have prepared a case study to plan the upgrade for the company. Based on the case study, which of the following steps will you suggest for configuring WebStore1?
Each correct answer represents a part of the solution. Choose two.
- A. Customize IIS 6.0 to display a legal warning page on the generation of the 404.2 and 404.3 errors.
- B. Configure IIS 6.0 on WebStore1 to scan the URL for known buffer overflow attacks.
- C. Move the WebStore1 server to the internal network.
- D. Move the computer account of WebStore1 to the Remote organizational unit (OU).
Answer: A,B
NEW QUESTION 49
Which of the following strategies allows a user to limit access according to unique hardware information supplied by a potential client?
- A. Extensible Authentication Protocol (EAP)
- B. MAC address filtering
- C. WEP
- D. Wireless Transport Layer Security (WTLS)
Answer: B
NEW QUESTION 50
Which of the following types of attacks is often performed by looking surreptitiously at the keyboard or monitor of an
employee's computer?
- A. Man-in-the-middle attack
- B. Shoulder surfing attack
- C. Denial-of-Service (DoS) attack
- D. Buffer-overflow attack
Answer: B
NEW QUESTION 51
Which of the following practices come in the category of denial of service attack?
Each correct answer represents a complete solution. Choose three.
- A. Sending lots of ICMP packets to an IP address
- B. Disrupting services to a specific computer
- C. Sending thousands of malformed packets to a network for bandwidth consumption
- D. Performing Back door attack on a system
Answer: A,B,C
NEW QUESTION 52
You work as a Senior Marketing Manager for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote desktop session. You suspected that some malicious attack was performed on the network of the company. You immediately called the incident response team to handle the situation who enquired the Network Administrator to acquire all relevant information regarding the malfunctioning. The Network Administrator informed the incident response team that he was reviewing the security of the network which caused all these problems. Incident response team announced that this was a controlled event not an incident.
Which of the following steps of an incident handling process was performed by the incident response team?
- A. Containment
- B. Identification
- C. Eradication
- D. Preparation
Answer: B
NEW QUESTION 53
A Denial-of-Service (DoS) attack is mounted with the objective of causing a negative impact on the performance of a
computer or network. It is also known as network saturation attack or bandwidth consumption attack. Attackers
perform DoS attacks by sending a large number of protocol packets to a network. The problems caused by a DoS
attack are as follows:
* Saturation of network resources
* Disruption of connections between two computers, thereby preventing communications between services
* Disruption of services to a specific computer
* Failure to access a Web site
* Increase in the amount of spam
Which of the following can be used as countermeasures against DoS attacks?
Each correct answer represents a complete solution. Choose all that apply.
- A. Blocking undesired IP addresses
- B. Disabling unneeded network services
- C. Applying router filtering
- D. Permitting network access only to desired traffic
Answer: A,B,C,D
NEW QUESTION 54
You want to connect to your friend's computer and run a Trojan on it. Which of the following tools will you use to accomplish the task?
- A. Hk.exe
- B. PSExec
- C. Remoxec
- D. GetAdmin.exe
Answer: B
Explanation:
Section: Volume C
NEW QUESTION 55
You are monitoring your network's behavior. You find a sudden increase in traffic on the network. It seems to come in bursts and emanate from one specific machine. You have been able to determine that a user of that machine is unaware of the activity and lacks the computer knowledge required to be responsible for a computer attack. What attack might this indicate?
- A. Denial of Service
- B. Spyware
- C. Session Hijacking
- D. Ping Flood
Answer: B
Explanation:
Section: Volume C
NEW QUESTION 56
You work as a Network Administrator in the SecureTech Inc. The SecureTech Inc. is using Linux-based server. Recently,
you have updated the password policy of the company in which the server will disable passwords after four trials.
What type of attack do you want to stop by enabling this policy?
- A. Replay
- B. XSS
- C. Cookie poisoning
- D. Brute force
Answer: D
NEW QUESTION 57
Your friend plans to install a Trojan on your computer. He knows that if he gives you a new version of chess.exe, you will definitely install the game on your computer. He picks up a Trojan and joins it with chess.exe. Which of the following tools are required in such a scenario?
Each correct answer represents a part of the solution. Choose three.
- A. Chess.exe
- B. Absinthe
- C. Yet Another Binder
- D. NetBus
Answer: A,C,D
Explanation:
Section: Volume B
NEW QUESTION 58
John works as a Professional Penetration Tester. He has been assigned a project to test the Website security of
www.we-are-secure Inc. On the We-are-secure Website login page, he enters ='or''=' as a username and successfully
logs on to the user page of the Web site. Now, John asks the we-aresecure Inc. to improve the login page PGIAC script.
Which of the following suggestions can John give to improve the security of the we-are-secure Website login page
from the SQL injection attack?
- A. Use the escapeshellcmd() function
- B. Use the escapeshellarg() function
- C. Use the mysql_real_escape_string() function for escaping input
- D. Use the session_regenerate_id() function
Answer: C
NEW QUESTION 59
Which of the following is the Web 2.0 programming methodology that is used to create Web pages that are dynamic and interactive?
- A. UML
- B. Ajax
- C. RSS
- D. XML
Answer: B
NEW QUESTION 60
You work as a System Administrator in SunSoft Inc. You are running a virtual machine on Windows Server 2003. The
virtual machine is protected by DPM. Now, you want to move the virtual machine to another host. Which of the
following steps can you use to accomplish the task?
Each correct answer represents a part of the solution. Choose all that apply.
- A. Run consistency check.
- B. Copy the virtual machine to the new server.
- C. Add the copied virtual machine to a protection group.
- D. Remove the original virtual machine from the old server and stop the protection for the original virtual machine.
Answer: B,C,D
NEW QUESTION 61
Which of the following strategies allows a user to limit access according to unique hardware information supplied by a
potential client?
- A. Extensible Authentication Protocol (EAP)
- B. MAC address filtering
- C. WEP
- D. Wireless Transport Layer Security (WTLS)
Answer: B
NEW QUESTION 62
Which of the following types of attacks is targeting a Web server with multiple compromised computers that are simultaneously sending hundreds of FIN packets with spoofed IP source IP addresses?
- A. Insertion attack
- B. DDoS attack
- C. Evasion attack
- D. Dictionary attack
Answer: B
NEW QUESTION 63
Adam, a malicious hacker is running a scan. Statistics of the scan is as follows:
Scan directed at open port:
ClientServer
192.5.2.92:4079 ---------FIN--------->192.5.2.110:23192.5.2.92:4079 <----NO RESPONSE---
---192.5.2.110:23
Scan directed at closed port:
ClientServer
192.5.2.92:4079 ---------FIN--------->192.5.2.110:23
192.5.2.92:4079<-----RST/ACK----------192.5.2.110:23
Which of the following types of port scan is Adam running?
- A. Idle scan
- B. XMAS scan
- C. ACK scan
- D. FIN scan
Answer: D
NEW QUESTION 64
......
How to Prepare For GCIH Certification Exam
Preparation Guide for GCIH Certification Exam
GCIH: Tips to survive if you don’t have time to read all the page
The GCIH certification is aimed at IT professionals who wish to demonstrate their competence and understanding of typical threats to corporate systems and networks. Workers who would benefit from getting GIAC GCIH certification are likely (or will be seeing for) workstations where information and skills to handle security incidents, understand common attack techniques, know that attack tools are required and how to defend themselves and react to such attacks when they occur. According to payscale.com, there may be up to $ 100,000 in salary for GCIH certification holders depending on their professional title. You can expect from $ 50,000 to $ 150,000 in roles where a GCIH certification complements the daily professional activities of the owner. Typical job titles for qualified GCIH professionals include Information Security Analyst Security engineer Responsible Information security Network Administrator / Firewall
Applicants who wish to obtain the GCIH certification must pass an exam consisting of 150 multiple-choice questions. The time allotted to complete the exam is 4 hours. The passing grade for the GCIH exam is 72%.
The exam is an “open book”, which means that candidates can bring any printed note, textbooks and any other similar material they want to the exam center (please note that there may be a limited office or space working in the test area). Electronic devices such as smartphones, tablets, USB sticks or similar devices are not allowed in the test area. Applicants will not have access to search files such as Word, PDF and the like, or to open Internet access.
GCIH exams are monitored by Pearson VUE test facilities worldwide. Always check in advance with the nearest exam center to verify current exam costs and the availability of the GCIH exam.
Before setting an exam date, candidates must open an account with SANS / GIAC.
Certified Incident Handler masters have described their ability to handle security incidents by learning attack techniques, vectors, and traditional tools, properly defending and/or responding to such attacks when they occur. The GCIH certification focuses on the methods used to detect, respond and resolve cybersecurity incidents. The professionals in charge of GCIH are qualified for practical and leadership positions within the incident management teams.
Updated GCIH Tests Engine pdf - All Free Dumps Guaranteed: https://www.validdumps.top/GCIH-exam-torrent.html
Latest GIAC Information Security GCIH Actual Free Exam Questions: https://drive.google.com/open?id=1rcJtLWgxQIDPVmp8OoTDtIyhBetDl-nw