GCIH Adam Practice Questions
The free GCIH: GIAC Certified Incident Handler questions that deal with adam, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #1
Adam works as an Incident Handler for Umbrella Inc. He has been sent to the California unit to train the members of the incident response team. As a demo project he asked members of the incident response team to perform the following actions: Remove the network cable wires. Isolate the system on a separate VLAN Use a firewall or access lists to prevent communication into or out of the system. Change DNS entries to direct traffic away from compromised system Which of the following steps of the incident handling process includes the above actions?
Correct answer: B
Explanation
Disconnecting cables, isolating the host on a separate VLAN, filtering its traffic and redirecting DNS all limit the damage and stop the incident spreading, which is the containment phase. Eradication would remove the malicious cause afterwards.
Question #8
Adam works as a Security Analyst for Umbrella Inc. Company has a Windows-based network. All computers run on Windows XP. Manager of the Sales department complains Adam about the unusual behavior of his computer. He told Adam that some pornographic contents are suddenly appeared on his computer overnight. Adam suspects that some malicious software or Trojans have been installed on the computer. He runs some diagnostics programs and Port scanners and found that the Port 12345, 12346, and 20034 are open. Adam also noticed some tampering with the Windows registry, which causes one application to run every time when Windows start. Which of the following is the most likely reason behind this issue?
Correct answer: C
Explanation
NetBus is a Windows remote access Trojan whose default listening ports are 12345, 12346 and 20034, and it adds a registry run key so it starts with Windows. The other tools listed are network mapping, log clearing and wireless discovery utilities.
Question #10
5.2.92:4079<-----RST/ACK----------192.5.2.110:23 Which of the following types of port scan is Adam running?
Correct answer: A
Continue with GCIH: GIAC Certified Incident Handler
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in GCIH: GIAC Certified Incident Handler, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All GCIH: GIAC Certified Incident Handler practice questions →
