
2022 GCIH dumps review - Professional Quiz Study Materials
GCIH Test Prep Training Practice Exam Questions Practice Tests
NEW QUESTION 201
Which of the following tools can be used for stress testing of a Web server?
Each correct answer represents a complete solution. Choose two.
- A. Internet bots
- B. Scripts
- C. Anti-virus software
- D. Spyware
Answer: A,B
NEW QUESTION 202
Adam works as an Incident Handler for Umbrella Inc. His recent actions towards the incident are not up to the standard norms of the company. He always forgets some steps and procedures while handling responses as they are very hectic to perform.
Which of the following steps should Adam take to overcome this problem with the least administrative effort?
- A. Appoint someone else to check the procedures.
- B. Create incident checklists.
- C. Create new sub-team to keep check.
- D. Create incident manual read it every time incident occurs.
Answer: B
NEW QUESTION 203
Which of the following is a technique of using a modem to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for computers, Bulletin board systems, and fax machines?
- A. Demon dialing
- B. Wardialing
- C. War driving
- D. Warkitting
Answer: B
NEW QUESTION 204
Which of the following statements are correct about spoofing and session hijacking?
Each correct answer represents a complete solution. Choose all that apply.
- A. Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target but the valid user
can be active. - B. Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is
disconnected. - C. Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target
and the valid user cannot be active. - D. Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is not
disconnected.
Answer: A,D
NEW QUESTION 205
You work as a Network Penetration tester in the Secure Inc. Your company takes the projects to test the security of various companies. Recently, Secure Inc. has assigned you a project to test the security of a Web site. You go to the Web site login page and you run the following SQL query:
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = '[email protected]'; DROP TABLE members; --'
What task will the above SQL query perform?
- A. Performs the XSS attacks.
- B. Deletes the rows of members table where email id is '[email protected]' given.
- C. Deletes the database in which members table resides.
- D. Deletes the entire members table.
Answer: D
Explanation:
Section: Volume B
NEW QUESTION 206
Which of the following tasks can be performed by using netcat utility?
Each correct answer represents a complete solution. Choose all that apply.
- A. Checking file integrity
- B. Port scanning and service identification
- C. Firewall testing
- D. Creating a Backdoor
Answer: B,C,D
NEW QUESTION 207
Victor works as a professional Ethical Hacker for SecureEnet Inc. He wants to scan the wireless network of the company. He uses a tool that is a free open-source utility for network exploration. The tool uses raw IP packets to determine the following:
What ports are open on our network systems.
What hosts are available on the network.
Identify unauthorized wireless access points.
What services (application name and version) those hosts are offering.
What operating systems (and OS versions) they are running.
What type of packet filters/firewalls are in use.
Which of the following tools is Victor using?
- A. Kismet
- B. Sniffer
- C. Nmap
- D. Nessus
Answer: C
NEW QUESTION 208
Which of the following statements about threats are true?
Each correct answer represents a complete solution. Choose all that apply.
- A. A threat is any circumstance or event with the potential of causing harm to a system in the form of destruction, disclosure, modification of data, or denial of service.
- B. A threat is a potential for violation of security which exists when there is a circumstance, capability, action, or event that could breach security and cause harm.
- C. A threat is a sequence of circumstances and events that allows a human or other agent to cause an information-related misfortune by exploiting vulnerability in an IT product.
- D. A threat is a weakness or lack of safeguard that can be exploited by vulnerability, thus causing harm to the information systems or networks.
Answer: A,B,C
NEW QUESTION 209
You discover that all available network bandwidth is being used by some unknown service. You discover that UDP packets are being used to connect the echo service on one machine to the chargen service on another machine. What kind of attack is this?
- A. Evil Twin
- B. Smurf
- C. Denial of Service
- D. Virus
Answer: C
NEW QUESTION 210
Which of the following attacks are examples of Denial-of-service attacks (DoS)?
Each correct answer represents a complete solution. Choose all that apply.
- A. Ping flood attack
- B. Smurf attack
- C. Fraggle attack
- D. Birthday attack
Answer: A,B,C
Explanation:
Section: Volume B
NEW QUESTION 211
Which of the following applications automatically calculates cryptographic hashes of all key system files that are to be
monitored for modifications?
- A. PrcView
- B. TCPView
- C. Tripwire
- D. Inzider
Answer: C
NEW QUESTION 212
Which of the following rootkits patches, hooks, or replaces system calls with versions that hide information about the
attacker?
- A. Boot loader rootkit
- B. Library rootkit
- C. Kernel level rootkit
- D. Hypervisor rootkit
Answer: B
NEW QUESTION 213
You check performance logs and note that there has been a recent dramatic increase in the amount of broadcast
traffic. What is this most likely to be an indicator of?
- A. DoS attack
- B. Misconfigured router
- C. Syn flood
- D. Virus
Answer: A
NEW QUESTION 214
You are the Security Consultant and have been hired to check security for a client's network. Your client has stated that he has many concerns but the most critical is the security of Web applications on their Web server. What should be your highest priority then in checking his network?
- A. Setting up IDS
- B. Port scanning
- C. Vulnerability scanning
- D. Setting up a honey pot
Answer: C
NEW QUESTION 215
In which of the following attacks does an attacker create the IP packets with a forged (spoofed) source IP address with the purpose of concealing the identity of the sender or impersonating another computing system?
- A. IP address spoofing
- B. Polymorphic shell code attack
- C. Rainbow attack
- D. Cross-site request forgery
Answer: A
NEW QUESTION 216
Adam works as a Security Administrator for Umbrella Inc. A project has been assigned to him to test the network security of the company. He created a webpage to discuss the progress of the tests with employees who were interested in following the test. Visitors were allowed to click on a company's icon to mark the progress of the test. Adam successfully embeds a keylogger. He also added some statistics on the webpage. The firewall protects the network well and allows strict Internet access.
How was security compromised and how did the firewall respond?
- A. Security was compromised as keylogger is invisible for firewall.
- B. Security was not compromised as the webpage was hosted internally.
- C. The attack was social engineering and the firewall did not detect it.
- D. The attack was Cross Site Scripting and the firewall blocked it.
Answer: C
NEW QUESTION 217
......
Exam Questions Answers Braindumps GCIH Exam Dumps PDF Questions: https://www.trainingdump.com/GIAC/GCIH-practice-exam-dumps.html
GCIH Exam Dumps, GCIH Practice Test Questions: https://drive.google.com/open?id=1AaJR67TaQtiWOL_4iYuL_tpBQ3Laz2cv