Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GIAC Systems and Network Auditor GSNA Exam Questions

Page: 1 / 28 Total 416 questions

Want more questions? Get Premium Access.

Question 1

Which of the following statements about data integrity of a container are true?

Each correct answer represents a complete solution. Choose two.

Correct Answer: A. It ensures that a hacker cannot alter the contents of an HTTP message while it is in transit from a container to a client.; C. Data integrity ensures that information has not been modified by a third party while it is in transit.
Explanation:

Data integrity ensures that information has not been modified, altered, or destroyed by a third party while it is in transit. Data integrity

ensures that the data received is same as the data that was sent. Moreover, no one can tamper with the data during transmission from

source to destination.

It also ensures that a hacker cannot alter the contents of an HTTP message while it is in transit from the container to the client. This will be

accomplished through the use of HTTPS. The HTTPS stands for Hypertext Transfer Protocol over Secure Socket Layer. The HTTPS encrypts and

decrypts the page requests and page information between the client browser and the Web server using a Secure Socket Layer.

Answer D is incorrect. This answer option describes confidentiality.

Answer B is incorrect. This answer option also describes confidentiality.


Question 2

You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to set the user login features on the systems with the shadow passwords. Which of the following Unix configuration files can you use to accomplish the task?

Correct Answer: B. /etc/login.defs
Explanation:

In Unix, the /etc/login.defs file is used by system administrators to set the user login features on the systems with the shadow passwords.

Answer A is incorrect. In Unix, the /etc/logrotate.conf file configures the logrotate program used for managing log files.

Answer C is incorrect. In Unix, the /etc/magic file contains the descriptions of various file formats for the file command.

Answer D is incorrect. In Unix, the /etc/filesystems file is used to set the filesystem probe order when filesystems are mounted with the

auto option.


Question 3

Which of the following are the countermeasures against WEP cracking?

Each correct answer represents a part of the solution. Choose all that apply.

Correct Answer: A. Using the longest key supported by hardware.; B. Changing keys often.; C. Using a non-obvious key.
Explanation:

A user can use some countermeasures to prevent WEP cracking. Although WEP is least secure, it should not be used. However, a user can

use the following methods to mitigate WEP cracking:

Use a non-obvious key.

Use the longest key supported by hardware.

Change keys often.

Use WEP in combination with other security features, such as rapid WEP key rotation and dynamic keying using 802.1x.

Consider WEP a deterrent, not a guarantee.

Answer D is incorrect. SSID stands for Service Set Identifier. It is used to identify a wireless network. SSIDs are case sensitive text

strings and have a maximum length of 32 characters. All wireless devices on a wireless network must have the same SSID in order to

communicate with each other.

The SSID on computers and the devices in WLAN can be set manually and automatically. Configuring the same SSID as that of the other

Wireless Access Points (WAPs) of other networks will create a conflict.

A network administrator often uses a public SSID that is set on the access point. The access point broadcasts SSID to all wireless devices

within its range. Some newer wireless access points have the ability to disable the automatic SSID broadcast feature in order to improve

network security.


Question 4

Which of the following recovery plans includes specific strategies and actions to deal with specific variances to assumptions resulting in a particular security problem, emergency, or state of affairs?

Correct Answer: D. Contingency plan
Explanation:

A contingency plan is a plan devised for a specific situation when things could go wrong. Contingency plans include specific strategies and

actions to deal with specific variances to assumptions resulting in a particular problem, emergency, or state of affairs. They also include a

monitoring process and triggers for initiating planned actions.

Answer A is incorrect. Disaster recovery is the process, policies, and procedures related to preparing for recovery or continuation of

technology infrastructure critical to an organization after a natural or human-induced disaster.

Answer C is incorrect. It deals with the plans and procedures that identify and prioritize the critical business functions that must be

preserved.

Answer B is incorrect. It includes the plans and procedures documented that ensure the continuity of critical operations during any

period where normal operations are impossible.


Question 5

Which of the following is a technique for creating Internet maps?

Each correct answer represents a complete solution. Choose two.

Correct Answer: A. AS PATH Inference; C. Active Probing
Explanation:

There are two prominent techniques used today for creating Internet maps:

Active probing: It is the first works on the data plane of the Internet and is called active probing. It is used to infer Internet topology

based on router adjacencies.

AS PATH Inference: It is the second works on the control plane and infers autonomous system connectivity based on BGP data.


Question 6

John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He is using the Linux operating system. He wants to use a wireless sniffer to sniff the We-are-secure network. Which of the following tools will he use to accomplish his task?

Correct Answer: B. Kismet
Explanation:

According to the scenario, John will use Kismet.

Kismet is a Linux-based 802.11 wireless network sniffer and intrusion detection system. It can work with any wireless card that supports raw

monitoring (rfmon) mode. Kismet can sniff 802.11b, 802.11a, 802.11g, and 802.11n traffic. Kismet can be used for the following tasks:

To identify networks by passively collecting packets

To detect standard named networks

To detect masked networks

To collect the presence of non-beaconing networks via data traffic

Answer D is incorrect. NetStumbler is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a,

802.11b, and 802.11g standards. It detects wireless networks and marks their relative position with a GPS.

Answer A is incorrect. WEPCrack is an open source tool that breaks IEEE 802.11 WEP secret keys.

Answer C is incorrect. Snadboy's Revelation is not a sniffer. It is used to see the actual password behind the asterisks.


Question 7

You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP based switched network. A root bridge has been elected in the switched network. You have installed a new switch with a lower bridge ID than the existing root bridge. What will happen?

Correct Answer: A. The new switch starts advertising itself as the root bridge.
Explanation:

The new switch starts advertising itself as the root bridge. It acts as it is the only bridge on the network. It has a lower Bridge ID than the existing root, so it is elected as the root bridge after the BPDUs converge and when all switches know about the new switch that it is the

better choice.

Answer D, B, and C are incorrect. All these are not valid options, according to the given scenario.


Question 8

What is the purpose of Cellpadding attribute of

tag?

Correct Answer: C. Cellpadding is used to set the space between the cell border and its content.
Explanation:

Cellpadding attribute is used to set the space, in pixels , between the cell border and its content. If you have not set the value of Cellpadding

attribute for a table, the browser takes the default value as 1.


Question 9

You are the security manager of Microliss Inc. Your enterprise uses a wireless network infrastructure with access points ranging 150-350 feet. The employees using the network complain that their passwords and important official information have been traced. You discover the following clues:

The information has proved beneficial to an other company.

The other company is located about 340 feet away from your office.

The other company is also using wireless network.

The bandwidth of your network has degraded to a great extent.

Which of the following methods of attack has been used?

Correct Answer: A. A piggybacking attack has been performed.
Explanation:

Piggybacking refers to access of a wireless Internet connection by bringing one's own computer within the range of another's wireless

connection, and using that service without the subscriber's explicit permission or knowledge. It is a legally and ethically controversial practice,

with laws that vary in jurisdictions around the world. While completely outlawed in some jurisdictions, it is permitted in others. The process of

sending data along with the acknowledgment is called piggybacking.

Answer C is incorrect. Bluebugging is an attack used only in a Bluetooth network. Bluebugging is a form of bluetooth attack often

caused by a lack of awareness. Bluebugging tools allow attacker to 'take control' of the victim's phone via the usage of the victim's Bluetooth

phone headset. It does this by pretending to be the users bluetooth headset and therefore 'tricking' the phone to obey its call commands.

Answer D is incorrect. A worm is a software program that uses computer networks and security holes to replicate itself from one

computer to another. It usually performs malicious actions, such as using the resources of computers as well as shutting down computers.

Answer B is incorrect. A Denial-of-Service (DoS) attack is mounted with the objective of causing a negative impact on the performance

of a computer or network. It is also known as a network saturation attack or bandwidth consumption attack. Attackers perform DoS attacks by

sending a large number of protocol packets to the network. The effects of a DoS attack are as follows:

Saturates network resources

Disrupts connections between two computers, thereby preventing communications between services

Disrupts services to a specific computer

Causes failure to access a Web site

Results in an increase in the amount of spam

A Denial-of-Service attack is very common on the Internet because it is much easier to accomplish. Most of the DoS attacks rely on the

weaknesses in the TCP/IP protocol.


Question 10

Which of the following tools can be used by a user to hide his identity?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B. IPchains; C. Proxy server; E. Anonymizer
Explanation:

A user can hide his identity using any firewall (such as IPChains), a proxy server, or an anonymizer.


Question 11

You have an online video library. You want to upload a directory of movies. Since this process will take several hours, you want to ensure that the process continues even after the terminal is shut down or session is closed. What will you do to accomplish the task?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B. Add the nohup command in front of the process.; D. Run the process inside a GNU Screen-style screen multiplexer.
Explanation:

Whenever the nohup command is added in front of any command or process, it makes the command or process run even after the terminal is

shut down or session is closed. All processes, except the 'at' and batch requests, are killed when a user logs out. If a user wants a

background process to continue running even after he logs out, he must use the nohup command to submit that background command. To

nohup running processes, press ctrl+z, enter 'bg' and enter 'disown'.

The other way to accomplish the task is to run the command/process inside a GNU Screen-style screen multiplexer, and then detach the

screen. GNU Screen maintains the illusion that the user is always logged in, and allows the user to reattach at any time. This has the

advantage of being able to continue to interact with the program once reattached (which is impossible with nohup alone).

Answer C is incorrect. The nohup command works when it is added in front of a command.

Answer A is incorrect. The bg command cannot run the command or process after the terminal is shut down or session is closed.


Question 12

You work as a Database Administrator for Dolliver Inc. The company uses Oracle 11g as its database. You have used the LogMiner feature for auditing purposes. Which of the following files store a copy of the data dictionary?

Each correct answer represents a complete solution. Choose two.

Correct Answer: A. Online redo log files; B. Operating system flat file
Explanation:

LogMiner requires a dictionary to translate object IDs into object names when it returns redo data to you. You have the following three

options to retrieve the data dictionary:

The Online catalog: It is the most easy and efficient option to be used. It is used when a database user have access to the source

database from which the redo log files were created. The other condition that should qualify is that there should be no changes to the

column definitions in the desired tables.

The Redo Log Files: This option is used when a database user does not have access to the source database from which the redo log

files were created and if there is any chances of changes to the column definitions of the desired tables.

An operating system flat file: Oracle does not recommend to use this option, but it is retained for backward compatibility. The reason

for not preferring the option is that it does not guarantee transactional consistency.

LogMiner is capable to access the Oracle redo logs. It keeps the complete record of all the activities performed on the database, and the

associated data dictionary, which is used to translate internal object identifiers and types to external names and data formats.

For offline analysis, LogMiner can be run on a separate database, using archived redo logs and the associated dictionary from the source

database.


Question 13

Which of the following backup sites takes the longest recovery time?

Correct Answer: C. Cold site
Explanation:

A cold backup site takes the longest recovery time. It is the most inexpensive type of backup site for an organization to operate. It does not

include backed up copies of data and information from the original location of the organization, nor does it include hardware already set up.

The lack of hardware contributes to the minimal startup costs of the cold site, but requires additional time following the disaster to have the

operation running at a capacity close to that prior to the disaster.

Answer D is incorrect. A hot site is a duplicate of the original site of the organization, with full computer systems as well as near-

complete backups of user data. Real time synchronization between the two sites may be used to completely mirror the data environment of

the original site using wide area network links and specialized software. Ideally, a hot site will be up and running within a matter of hours or

even less.

Answer A is incorrect. Although a mobile backup site provides rapid recovery, it does not provide full recovery in time. Hence, a hot site

takes the shortest recovery time.

Answer B is incorrect. A warm site is, quite logically, a compromise between hot and cold. These sites will have hardware and

connectivity already established, though on a smaller scale than the original production site or even a hot site. Warm sites will have backups

on hand, but they may not be complete and may be between several days and a week old. An example would be backup tapes sent to the

warm site by courier.


Question 14

You work as the Network Administrator for McNeil Inc. The company has a Unix-based network. You want to identify the list of users with special privileges along with the commands that they can execute. Which of the following Unix configuration files can you use to accomplish the task?

Correct Answer: D. /etc/sudoers
Explanation:

In Unix, the /etc/sudoers file contains a list of users with special privileges along with the commands that they can execute.

Answer A is incorrect. In Unix, the /proc/meminfo file shows information about the memory usage, both physical and swap.

Answer B is incorrect. In Unix, the /etc/sysconfig/amd file is the configuration file that is used to configure the auto mount daemon.

Answer C is incorrect. In Unix, the /proc/modules file shows the kernel modules that are currently loaded.


Question 15

You have detected what appears to be an unauthorized wireless access point on your network. However this access point has the same MAC

address as one of your real access points and is broadcasting with a stronger signal. What is this called?

Correct Answer: B. The evil twin attack
Explanation:

In the evil twin attack, a rogue wireless access point is set up that has the same MAC address as one of your legitimate access points. That

rogue WAP will often then initiate a denial of service attack on your legitimate access point making it unable to respond to users, so they are

redirected to the 'evil twin'.

Answer A is incorrect. Blue snarfing is the process of taking over a PDA.

Answer D is incorrect. A DOS may be used as part of establishing an evil twin, but this attack is not specifically for denial of service.

Answer C is incorrect. While you must clone a WAP MAC address, the attack is not called WAP cloning.