Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Incident Handler

Domain 5Objective 1

Scanning and Mapping GCIH Practice Questions (Page 3)

Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
9concepts

Questions 11–15

  1. 11application · medium

    You are investigating a suspicious host on your network. You need to determine its operating system without sending any packets to the host, to avoid alerting the attacker. Which technique should you use?

    Select an answer first
  2. 12foundation · easy

    In the context of incident handling, what is the primary purpose of network scanning?

    Select an answer first
  3. 13foundation · easy

    Which host discovery technique relies on the Address Resolution Protocol (ARP) and is most effective on a local Ethernet network?

    Select an answer first
  4. 14foundation · easy

    During the incident handling process, which phase typically involves network scanning to gather information about the victim environment?

    Select an answer first
  5. 15application · medium

    Your organization has experienced several unauthorized port scans from the internet. You want to implement a defensive measure that can detect and potentially block these scans at the network perimeter. Which of the following is the most effective approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.