
GIAC Certified Incident Handler
Domain 5Objective 1
Scanning and Mapping GCIH Practice Questions (Page 2)
Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 6–10
- 6
You are conducting an authorized security assessment and need to scan a target network that is protected by an intrusion prevention system (IPS). The IPS is configured to block source IPs that send more than 10 SYN packets per second. You need to complete a port scan of a single host with 1000 ports without being blocked. Which approach is most effective?
Select an answer first - 7
Which host discovery technique sends a TCP packet with the SYN flag set to a specific port and considers the host alive if it receives a SYN-ACK or RST response?
Select an answer first - 8
You have run an Nmap scan against a server and received the following output snippet: PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https 3306/tcp filtered mysql Based on this output, what is the most accurate interpretation?
Select an answer first - 9
During an incident investigation, you have identified an open port on a compromised server. You need to determine the exact service and version to check for known vulnerabilities. The server is behind a firewall that only allows traffic from your IP address to that specific port. You also need to avoid crashing the service, which is known to be unstable. Which approach is most appropriate?
Select an answer first - 10
Which OS fingerprinting technique involves sending crafted packets to a target and analyzing the responses to determine the operating system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.