Get 2023 Free GIAC GCIH Exam Practice Materials Collection [Q162-Q181]

Share

Get 2023 Free GIAC GCIH Exam Practice Materials Collection

Get Latest and 100% Accurate GCIH Exam Questions

NEW QUESTION # 162
Rick works as a Computer Forensic Investigator for BlueWells Inc. He has been informed that some confidential information is being leaked out by an employee of the company. Rick suspects that someone is sending the information through email. He checks the emails sent by some employees to other networks. Rick finds out that Sam, an employee of the Sales department, is continuously sending text files that contain special symbols, graphics, and signs. Rick suspects that Sam is using the Steganography technique to send data in a disguised form. Which of the following techniques is Sam using?
Each correct answer represents a part of the solution. Choose all that apply.

  • A. Text Semagrams
  • B. Perceptual masking
  • C. Technical steganography
  • D. Linguistic steganography

Answer: A,D


NEW QUESTION # 163
Which of the following statements about buffer overflow is true?

  • A. It manages security credentials and public keys for message encryption.
  • B. It is a false warning about a virus.
  • C. It is a condition in which an application receives more data than it is configured to accept.
  • D. It is a collection of files used by Microsoft for software updates released between major service pack releases.

Answer: C


NEW QUESTION # 164
Which of the following steps can be taken as countermeasures against sniffer attacks?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Use encrypted protocols for all communications.
  • B. Use tools such as StackGuard and Immunix System to avoid attacks.
  • C. Reduce the range of the network to avoid attacks into wireless networks.
  • D. Use switches instead of hubs since they switch communications, which means that information is delivered only to the predefined host.

Answer: A,C,D


NEW QUESTION # 165
Which of the following tools can be used for network sniffing as well as for intercepting conversations through session hijacking?

  • A. IPChains
  • B. Hunt
  • C. Tripwire
  • D. Ethercap

Answer: B


NEW QUESTION # 166
Which of the following wireless network security solutions refers to an authentication process in which a user can
connect wireless access points to a centralized server to ensure that all hosts are properly authenticated?

  • A. IEEE 802.1x
  • B. Wi-Fi Protected Access 2 (WPA2)
  • C. Wired Equivalent Privacy (WEP)
  • D. Remote Authentication Dial-In User Service (RADIUS)

Answer: A


NEW QUESTION # 167
You are the Administrator for a corporate network. You are concerned about denial of service attacks.
Which of the following measures would be most helpful in defending against a Denial-of-Service (DoS) attack?

  • A. Place a honey pot in the DMZ.
  • B. Implement a strong password policy.
  • C. Implement network based antivirus.
  • D. Shorten the timeout for connection attempts.

Answer: D

Explanation:
Section: Volume B


NEW QUESTION # 168
Which of the following Denial-of-Service (DoS) attacks employ IP fragmentation mechanism?
Each correct answer represents a complete solution. Choose two.

  • A. SYN flood attack
  • B. Land attack
  • C. Teardrop attack
  • D. Ping of Death attack

Answer: C,D

Explanation:
Section: Volume A
Explanation


NEW QUESTION # 169
You work as a Network Penetration tester in the Secure Inc. Your company takes the projects to test the security of
various companies. Recently, Secure Inc. has assigned you a project to test the security of a Web site. You go to the
Web site login page and you run the following SQL query:
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = '[email protected]'; DROP TABLE members; --'
What task will the above SQL query perform?

  • A. Deletes the database in which members table resides.
  • B. Performs the XSS attacks.
  • C. Deletes the entire members table.
  • D. Deletes the rows of members table where email id is '[email protected]' given.

Answer: C


NEW QUESTION # 170
John works as a Network Administrator for Net Perfect Inc. The company has a Windows-based network.
The company uses Check Point SmartDefense to provide security to the network of the company. On the HTTP servers of the company, John defines a rule for dropping any kind of userdefined URLs. Which of the following types of attacks can be prevented by dropping the user-defined URLs?

  • A. Morris worm
  • B. Code red worm
  • C. PTC worms and mutations
  • D. Hybrid attacks

Answer: C


NEW QUESTION # 171
Which of the following rootkits patches, hooks, or replaces system calls with versions that hide information about the attacker?

  • A. Library rootkit
  • B. Boot loader rootkit
  • C. Hypervisor rootkit
  • D. Kernel level rootkit

Answer: A

Explanation:
Section: Volume B


NEW QUESTION # 172
Which of the following types of malware can an antivirus application disable and destroy?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Adware
  • B. Crimeware
  • C. Rootkit
  • D. Virus
  • E. Trojan
  • F. Worm

Answer: C,D,E,F


NEW QUESTION # 173
Which of the following is a method of gaining access to a system that bypasses normal authentication?

  • A. Trojan horse
  • B. Smurf
  • C. Teardrop
  • D. Back door

Answer: D


NEW QUESTION # 174
Which of the following steps of incident response is steady in nature?

  • A. Eradication
  • B. Recovery
  • C. Containment
  • D. Preparation

Answer: D


NEW QUESTION # 175
Adam works as a Security Administrator for Umbrella Inc. A project has been assigned to him to test the network security of the company. He created a webpage to discuss the progress of the tests with employees who were interested in following the test. Visitors were allowed to click on a company's icon to mark the progress of the test. Adam successfully embeds a keylogger. He also added some statistics on the webpage. The firewall protects the network well and allows strict Internet access.
How was security compromised and how did the firewall respond?

  • A. The attack was social engineering and the firewall did not detect it.
  • B. Security was not compromised as the webpage was hosted internally.
  • C. Security was compromised as keylogger is invisible for firewall.
  • D. The attack was Cross Site Scripting and the firewall blocked it.

Answer: A


NEW QUESTION # 176
CORRECT TEXT
Fill in the blank with the correct numeric value.
ARP poisoning is achieved in ______ steps.

Answer:

Explanation:
2


NEW QUESTION # 177
Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason.
Which of the following mistakes made by Jason helped the Forensic Investigators catch him?

  • A. Jason did not perform port scanning.
  • B. Jason did not perform foot printing.
  • C. Jason did not perform covering tracks.
  • D. Jason did not perform a vulnerability assessment.
  • E. Jason did not perform OS fingerprinting.

Answer: C

Explanation:
Section: Volume A


NEW QUESTION # 178
Which of the following is the best method of accurately identifying the services running on a victim host?

  • A. Use of the manual method of telnet to each of the open ports.
  • B. Use of a vulnerability scanner to try to probe each port to verify which service is running.
  • C. Use of a port scanner to scan each port to confirm the services running.
  • D. Use of hit and trial method to guess the services and ports of the victim host.

Answer: A


NEW QUESTION # 179
Many organizations create network maps of their network system to visualize the network and understand the
relationship between the end devices and the transport layer that provide services.
Which of the following are the techniques used for network mapping by large organizations?
Each correct answer represents a complete solution. Choose three.

  • A. Active Probing
  • B. Packet crafting
  • C. Route analytics
  • D. SNMP-based approaches

Answer: A,C,D


NEW QUESTION # 180
You work as a Security Administrator for Net Perfect Inc. The company has a Windows-based network. You want to use a scanning technique which works as a reconnaissance attack. The technique should direct to a specific host or network to determine the services that the host offers.
Which of the following scanning techniques can you use to accomplish the task?

  • A. Nmap
  • B. IDLE scan
  • C. Host port scan
  • D. SYN scan

Answer: C

Explanation:
Section: Volume B


NEW QUESTION # 181
......

Maximum Grades By Making ready With GCIH Dumps: https://www.testvalid.com/GCIH-exam-collection.html

Prepare GCIH Exam Questions Recently Updated Questions: https://drive.google.com/open?id=1oZrK4GQ8RJmK5luCZIlxINoiKGzwSVXf