GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 4 of 18.

  1. Question 34: A popular forum, where ICS techniques are discussed, loads scripts and ads from multiple external sites. Which attack can an adversary use to leverage this sit…
  2. Question 35: What action does the following command perform? C:\DefenderCheck.exe .\giac1.exe
  3. Question 36: How could an attacker set up a persistent backdoor listener to a login shell on TCP port 53 using netcat on a Linux system?
  4. Question 37: What hash type is being cracked in the command below? hashcat -m 1000 -a 0 customer.ntds wordlist.txt --potfile-path ./hashcat.potfile
  5. Question 39: What information is commonly found in both the header and the possession log of a Chain of Custody?
  6. Question 41: An engineer is using Hashcat to brute force passwords from a file of hashes. How should the following hash be handled in the scenario? aad3b435b51404eeaad3b435…
  7. Question 42: Which is the normal response from live hosts to the discovery packets sent during a default Nmap sweep?
  8. Question 43: Which malware investigation approach provides a detailed log of a system’s file system, network, registry and process activities?
  9. Question 44: What is a common characteristic of both a watering hole attack and a drive-by attack?
  10. Question 46: An organization has an SSH server that was compromised, but later eradicated and recovered. The system disks were wiped clean, the OS reinstalled, and patches…