
GIAC Certified Incident Handler
Domain 5Objective 1
Scanning and Mapping GCIH Practice Questions (Page 5)
Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 21–25
- 21
What information is typically obtained from a banner grab during service version detection?
Select an answer first - 22
You are responding to an incident where an attacker has compromised a server. You need to identify the operating system of the attacker's machine from a pcap capture, but you cannot send any traffic to the attacker. Which technique is most appropriate?
Select an answer first - 23
You are on a local Ethernet segment and need to discover live hosts quickly. You have Nmap installed and you are concerned about being detected by the network's IDS, which is known to alert on ICMP and TCP SYN traffic. Which Nmap host discovery technique is most appropriate in this situation?
Select an answer first - 24
You have captured a pcap file from a suspected compromised host. You need to identify which services were likely running on the host based on the traffic. Which approach is most appropriate?
Select an answer first - 25
You are analyzing a service that returns a banner saying '220 FTP server ready' but does not respond to standard FTP commands. You need to determine the actual service behind the banner. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.