GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 14 of 18.

  1. Question 158: The Network Operations Center has identified and escalated an active denial of service incident on the mail server and several externally facing web sites to t…
  2. Question 159: Which of the following can be used in a USB attack to bypass authentication by hijacking the password libraries on a Windows system?
  3. Question 160: Which of the following is the difference between SSL and S-HTTP?
  4. Question 161: If virtual machines are relatively easy for an attacker to detect, the next best thing might be to put so much honey in your honeypot, attackers won't be able…
  5. Question 162: An attacker is tunneling TLS encrypted traffic within ICMP echo and reply packets. How will most network appliances see this?
  6. Question 163: Suppose a web application builds the SQL command "select PhoneNumber from contacts where Company = '[value]';". What would the result likely be if an attacker…
  7. Question 164: As related to buffer overflows, what is the purpose of the Instruction Pointer?
  8. Question 165: Which stage of an attack typically involves little or no direct interaction with the attack target(s)?
  9. Question 166: A client wants a system so that they can monitor connection queues on network equipment for too many half-open connections, as well as look for bandwidth consu…
  10. Question 167: You are a member of your organization's security team. A new ticket just came into your service desk and was escalated to you. One of the system administrators…