GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 3 of 18.

  1. Question 23: What UNIX component can be used to enforce password complexity requirements?
  2. Question 24: Which endpoint security bypass technique leverages existing system tools instead of adding executable?
  3. Question 25: After running the command shown below, which output field contains the user’s cleartext account name? aws sts get-caller-identity
  4. Question 26: Which of the following SSH commands will start a SOCKS proxy server on the local system?
  5. Question 27: Which Windows process would an attacker target to steal credentials from a user who logs into applications with a Password Manager?
  6. Question 28: What is the outcome of the command below? hashcat -m 0 -a 3 ntds.dat --potfile-path ntds.potfile -1 ?d?d?d?d?d?d
  7. Question 29: What hash type is being cracked in the command below? hashcat -m 1800 -a 0 customer.ntds wordlist.txt --potfile-path ./hashcat.potfile
  8. Question 31: An investigator performing an initial analysis of a memory image identified a suspicious URL while using the strings utility. A second investigator attempting…
  9. Question 32: The tools and techniques used in memory analysis closely resembles which other type of investigation?
  10. Question 33: Which of the following persistence techniques will be identified using the Autoruns utility?