GIAC Certified Incident Handler (GCIH) Free Practice Exam Questions

178 real GIAC Certified Incident Handler (GCIH) exam questions with answers and AI explanations. GIAC certification prep — page 5 of 18.

  1. Question 47: An attacker has determined a web application is running the SQL command shown below. What could she enter for VALUE to get a list of all email addresses in the…
  2. Question 50: Which of the following network applications is better suited for using a connection-oriented protocol than a stateless protocol?
  3. Question 52: Which volatility plugin shows the command line path for a recently launched application?
  4. Question 53: A security auditor is using John the Ripper to review password strength on Windows machines. The auditor knows that the company requires a 15-character minimum…
  5. Question 54: What is the Linux administrator doing with the commands below? $ rpcclient -U fezzik florin rpcclient
    gt; lsaenumsid
  6. Question 55: When probing for command injection opportunities on a remote host, why would an attacker target her own address space from the remote host?
  7. Question 57: How would an attacker hide an executable from being viewed by Windows Explorer?
  8. Question 59: An attacker needs to relay SMB requests to another system outside of the local subnet using Responder. Which command arguments will achieve this goal?
  9. Question 60: A spike in Event ID 4625 is found in Windows event logs. Looking at individual accounts across the domain, no more than 5 failed logins are found for any singl…
  10. Question 61: Which PowerShell cmdlet will display the command line parameters used to launch a Windows process?