GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 12 of 18.

  1. Question 136: Inspecting developer code for functions like system, exec, and popen is recommended to reduce the likelihood of what type of public-facing attack?
  2. Question 137: Which of the following can the rpcclient application do?
  3. Question 139: What is the definition of an event as it applies to incident handling?
  4. Question 140: Which of the following is the most effective technique for identifying live client systems on a LAN?
  5. Question 141: An attacker has tricked a user into executing content he placed on a social networking site. The malicious content executes in the victim's browser and allows…
  6. Question 142: A system administrator finds the entry below in an Apache log. What can be done to mitigate against this? 192.168.116.201 - - [22/Apr/2016:13:43:26 -0400] `GET…
  7. Question 143: Firekiller 2000 is an example of a __________.
  8. Question 144: Which of the following packets saved in the file pingout.pcap would be returned with the following Berkley Packet Filters? tcpdump -nn -r pingout.pcap `˜icmp a…
  9. Question 145: Which of the following are countermeasures to prevent unauthorized database access attacks? Each correct answer represents a complete solution. (Choose all tha…
  10. Question 146: Which of the following is an effective method of detecting a covert communication tunnel such as ptunnel?