
GIAC Certified Incident Handler
Domain 5Objective 1
Scanning and Mapping GCIH Practice Questions (Page 9)
Part of the Network and Infrastructure Security domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 41–45
- 41
During an incident investigation, you need to determine the operating system of a compromised host without sending any packets directly to that host. You have access to a network tap that captures traffic between the host and other systems. Which approach is most appropriate?
Select an answer first - 42
Which Nmap flag is used to perform a TCP SYN scan?
Select an answer first - 43
You are conducting a penetration test against a network with a strict egress firewall that only allows outbound TCP connections to ports 80 and 443. You need to scan internal hosts from outside, but the firewall blocks all inbound traffic. Which technique could you use to perform the scan?
Select an answer first - 44
Which evasion technique uses multiple spoofed source IP addresses in addition to the real scanner's IP to confuse intrusion detection systems?
Select an answer first - 45
You have Nmap output showing port 22 open with service 'ssh' and version 'OpenSSH 7.2p2'. You also see port 8080 open with service 'http-proxy'. You need to prioritize which service to investigate for a potential vulnerability. Which factor should most influence your decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GCIH
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCIH” is a trademark of its owner, used for identification only.