
GIAC Certified Incident Handler
Domain 5Objective 1
Scanning and Mapping GCIH Practice Questions (Page 7)
Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 31–35
- 31
Your security team wants to reduce the risk of internal reconnaissance by limiting the information available to attackers. You need to implement a defensive measure that makes it harder for attackers to map the network. Which action is most effective?
Select an answer first - 32
Which countermeasure can limit the effectiveness of host discovery scans by preventing the network from responding to ICMP echo requests?
Select an answer first - 33
You need to perform a comprehensive scan of a web server to identify open ports, running services, and the operating system. You want to use a single Nmap command that enables all these features. Which command should you use?
Select an answer first - 34
Which method is used to determine the version of a service that does not provide a banner, by analyzing its responses to various probes?
Select an answer first - 35
You are performing a port scan against a server that has a stateful firewall. You need to determine which TCP ports are open, but you want to avoid completing the TCP handshake to reduce the chance of being logged. Which Nmap scan type should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.