Exam Details

  • Exam Code
    :GCIH
  • Exam Name
    :GIAC Certified Incident Handler
  • Certification
    :GIAC Information Security
  • Vendor
    :GIAC
  • Total Questions
    :705 Q&As
  • Last Updated
    :May 14, 2024

GIAC GIAC Information Security GCIH Questions & Answers

  • Question 701:

    Adam works as a Security Administrator for Umbrella Inc. A project has been assigned to him to test the network security of the company. He created a webpage to discuss the progress of the tests with employees who were interested in

    following the test. Visitors were allowed to click on a company's icon to mark the progress of the test. Adam successfully embeds a keylogger. He also added some statistics on the webpage. The firewall protects the network well and allows

    strict Internet access.

    How was security compromised and how did the firewall respond?

    A. The attack was social engineering and the firewall did not detect it.

    B. Security was not compromised as the webpage was hosted internally.

    C. The attack was Cross Site Scripting and the firewall blocked it.

    D. Security was compromised as keylogger is invisible for firewall.

  • Question 702:

    You work as a Network Administrator for Infonet Inc. The company has a Windows Server 2008 Active Directory-based single domain single forest network. The company has three Windows 2008 file servers, 150 Windows XP Professional,

    thirty UNIX-based client computers. The network users have identical user accounts for both Active Directory and the UNIX realm. You want to ensure that the UNIX clients on the network can access the file servers. You also want to ensure

    that the users are able to access all resources by logging on only once, and that no additional software is installed on the UNIX clients.

    What will you do to accomplish this task?

    Each correct answer represents a part of the solution. (Choose two.)

    A. Configure a distributed file system (Dfs) on the file server in the network.

    B. Enable the Network File System (NFS) component on the file servers in the network.

    C. Configure ADRMS on the file servers in the network.

    D. Enable User Name Mapping on the file servers in the network.

  • Question 703:

    Which of the following methods can be used to detect session hijacking attack?

    A. nmap

    B. Brutus

    C. ntop

    D. sniffer

  • Question 704:

    Adam works as a Network Administrator for PassGuide Inc. He wants to prevent the network from DOS attacks. Which of the following is most useful against DOS attacks?

    A. SPI

    B. Distributive firewall

    C. Honey Pot

    D. Internet bot

  • Question 705:

    Adam works as a Security Administrator for Umbrella Inc. A project has been assigned to him to secure access to the network of the company from all possible entry points. He segmented the network into several subnets and installed firewalls all over the network. He has placed very stringent rules on all the firewalls, blocking everything in and out except the ports that must be used. He does need to have port 80 open since his company hosts a website that must be accessed from the Internet. Adam is still worried about the programs like Hping2 that can get into a network through covert channels.

    Which of the following is the most effective way to protect the network of the company from an attacker using Hping2 to scan his internal network?

    A. Block all outgoing traffic on port 21

    B. Block all outgoing traffic on port 53

    C. Block ICMP type 13 messages

    D. Block ICMP type 3 messages

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only GIAC exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your GCIH exam preparations and GIAC certification application, do not hesitate to visit our Vcedump.com to find your solutions here.