
GIAC Certified Incident Handler
Domain 5Objective 1
Scanning and Mapping GCIH Practice Questions (Page 4)
Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 16–20
- 16
As a security administrator, you want to detect unauthorized port scans on your internal network. You have a network tap and a server that can analyze traffic. Which defensive measure is most effective for detecting a SYN scan?
Select an answer first - 17
You are analyzing a scan result that shows port 21/tcp is open. You need to determine if the service running is an FTP server and what version it is. Which of the following is the most reliable method to accomplish this?
Select an answer first - 18
Which port scanning technique sends a packet with the FIN, URG, and PUSH flags set, and expects closed ports to respond with an RST packet?
Select an answer first - 19
Which OS fingerprinting technique is considered stealthier because it does not send any packets to the target host?
Select an answer first - 20
You are conducting a red-team exercise against a network that uses an intrusion detection system (IDS) configured to alert on TCP SYN packets sent to multiple ports on the same host. You need to perform a port scan while minimizing the chance of triggering the IDS. Which technique is most effective for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.