Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GIAC Certified Incident Handler GCIH Exam Questions

Page: 1 / 23 Total 335 questions

Want more questions? Get Premium Access.

Question 1

John visits an online shop that stores the IDs and prices of the items to buy in a cookie. After selecting the items that he wants to buy, the attacker changes the price of the item to 1.

Original cookie values:

ItemID1=2

ItemPrice1=900

ItemID2=1

ItemPrice2=200

Modified cookie values:

ItemID1=2

ItemPrice1=1

ItemID2=1

ItemPrice2=1

Now, he clicks the Buy button, and the prices are sent to the server that calculates the total price.

Which of the following hacking techniques is John performing?

Correct Answer: D. Cookie poisoning

Question 2

John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server. He presents a report to the company describing the symptoms of the Trojan. A summary of the report is given below:

Once this Trojan has been installed on the computer, it searches Notpad.exe, renames it Note.com, and then copies itself to the computer as Notepad.exe. Each time Notepad.exe is executed, the Trojan executes and calls the original Notepad to avoid being noticed.

Which of the following Trojans has the symptoms as the one described above?

Correct Answer: B. Qaz

Question 3

Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?

Correct Answer: B. Nessus

Question 4

Which of the following types of malware does not replicate itself but can spread only when the

circumstances are beneficial?

Correct Answer: D. Trojan horse

Question 5

You want to perform passive footprinting against we-are-secure Inc. Web server. Which of the following tools will you use?

Correct Answer: D. Netcraft

Question 6

Which of the following is used to gather information about a remote network protected by a firewall?

Correct Answer: D. Firewalking

Question 7

Which of the following statements about threats are true?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B. A threat is a potential for violation of security which exists when there is a circumstance, capability, action, or event that could breach security and cause harm.; C. A threat is a sequence of circumstances and events that allows a human or other agent to cause an information-related misfortune by exploiting vulnerability in an IT product.; D. A threat is any circumstance or event with the potential of causing harm to a system in the form of destruction, disclosure, modification of data, or denial of service.

Question 8

Which of the following types of attacks slows down or stops a server by overloading it with requests?

Correct Answer: A. DoS attack

Question 9

Which of the following Linux rootkits allows an attacker to hide files, processes, and network connections?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: C. Adore; D. Knark

Question 10

You want to scan your network quickly to detect live hosts by using ICMP ECHO Requests. What type of scanning will you perform to accomplish the task?

Correct Answer: D. Ping sweep scan

Question 11

Which of the following functions can be used as a countermeasure to a Shell Injection attack?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: A. escapeshellarg(); D. escapeshellcmd()

Question 12

Adam, a novice computer user, works primarily from home as a medical professional. He just bought a brand new Dual Core Pentium computer with over 3 GB of RAM. After about two months of working on his new computer, he notices that it is not running nearly as fast as it used to. Adam uses antivirus software, anti-spyware software, and keeps the computer up-to-date with Microsoft patches. After another month of working on the computer, Adam finds that his computer is even more noticeably slow. He also notices a window or two pop-up on his screen, but they quickly disappear. He has seen these windows show up, even when he has not been on the Internet. Adam notices that his computer only has about 10 GB of free space available. Since his hard drive is a 200 GB hard drive, Adam thinks this is very odd.

Which of the following is the mostly likely the cause of the problem?

Correct Answer: A. Computer is infected with the stealth kernel level rootkit.

Question 13

You work as a Network Administrator for InformSec Inc. You find that the TCP port number 23476 is open on your server. You suspect that there may be a Trojan named Donald Dick installed on your server. Now you want to verify whether Donald Dick is installed on it or not. For this, you want to know the process running on port 23476, as well as the process id, process name, and the path of the process on your server. Which of the following applications will you most likely use to accomplish the task?

Correct Answer: D. Fport

Question 14

Which of the following scanning tools is also a network analysis tool that sends packets with

nontraditional IP stack parameters and allows the scanner to gather information from the response packets generated?

Correct Answer: D. GIACing

Question 15

You work as a Security Administrator for Net Perfect Inc. The company has a Windows-based network. You want to use a scanning technique which works as a reconnaissance attack. The technique should direct to a specific host or network to determine the services that the host offers.

Which of the following scanning techniques can you use to accomplish the task?

Correct Answer: D. Host port scan