GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 10 of 18.

  1. Question 114: In the DNS Zone transfer enumeration, an attacker attempts to retrieve a copy of the entire zone file for a domain from a DNS server. The information provided…
  2. Question 115: Which of the following types of malware can an antivirus application disable and destroy? Each correct answer represents a complete solution. (Choose all that…
  3. Question 116: You work as an Incident handling manager for a company. The public relations process of the company includes an event that responds to the e-mails queries. But…
  4. Question 117: Which of the following tools uses common UNIX/Linux tools like the strings and grep commands to search core system programs for signatures of the rootkits?
  5. Question 118: For what purpose would an auditor obtain a copy of the /etc/passwd file for a password audit of a linux machine?
  6. Question 119: Which web application log keyword would be associated with a SQL injection attack?
  7. Question 120: What tool would an incident handler use to search for all autostart extensibility points (ASEPs) on a Windows host?
  8. Question 122: While examining multiple compromised systems, an investigator lists a priority for each machine based on executive input and the type of service and data each…
  9. Question 123: An organization needs to protect its PHP web applications from Cross-Site Scripting attacks. Which action should they take?
  10. Question 124: What does the term any instruct tcpdump to capture in the following command? tcpdump -A -i any 'port 21 && host 192.168.100.1'