Home/giac/Free GIAC GCIH Actual Exam Questions

Free GIAC GCIH Actual Exam Questions

The questions for this exam were last updated on January 7, 2026

Dumps Box (DumpsBox) offers up-to-date practice exam questions for GCIH certification exam which are developed and validated by GIAC subject domain experts certified in GIAC GCIH . These practice questions are update regularly as we keep an eye on any recent changes in GCIH syllabus, and when there is update our team quickly adjusts the questions. This commitment to providing the best quality exam prep material to certification aspirants is what makes DumpsBox.com the best certification exam prep website. On top of that, our strong, yet strictly moderated, community based feedback keeps the content clean and current. Each question has helpful community discussion that provides it extra perspective and introduces helpful resources for better exam preparation. This also saves students from other outdated practice questions or illicit exam dumps that can have adverse affects on career. Browse through our GIAC GCIH exam questions and pass your exam on first try.

Question No. 1
You execute the following netcat command:
c:\target\nc -1 -p 53 -d -e cmd.exe
What action do you want to perform by issuing the above command?
Select one option, then reveal solution.
Question No. 2
John works as a Network Administrator for We-are-secure Inc. He finds that TCP port 7597 of the
Weare- secure server is open. He suspects that it may be open due to a Trojan installed on the server.
He presents a report to the company describing the symptoms of the Trojan. A summary of the
report is given below:
Once this Trojan has been installed on the computer, it searches Notpad.exe, renames it Note.com,
and then copies itself to the computer as Notepad.exe. Each time Notepad.exe is executed, the
Trojan executes and calls the original Notepad to avoid being noticed.
Which of the following Trojans has the symptoms as the one described above?
Select one option, then reveal solution.
Question No. 3
Which of the following types of attacks come under the category of hacker attacks?
Each correct answer represents a complete solution. Choose all that apply.
Select all that apply, then reveal solution.
Question No. 4
You are hired as a Database Administrator for Jennifer Shopping Cart Inc. You monitor the server
health through the System Monitor and found that there is a sudden increase in the number of
logins.
A case study is provided in the exhibit. Which of the following types of attack has occurred?
(Click the Exhibit button on the toolbar to see the case study.)
Select one option, then reveal solution.
Question No. 5
Peter works as a Network Administrator for the PassGuide Inc. The company has a Windows-based
network. All client computers run the Windows XP operating system. The employees of the company
complain that suddenly all of the client computers have started working slowly. Peter finds that a
malicious hacker is attempting to slow down the computers by flooding the network with a large
number of requests. Which of the following attacks is being implemented by the malicious hacker?
Select one option, then reveal solution.
Question No. 6
TCP/IP stack fingerprinting is the passive collection of configuration attributes from a remote device
during standard layer 4 network communications. The combination of parameters may then be used
to infer the remote operating system (OS fingerprinting), or incorporated into a device fingerprint.
Which of the following Nmap switches can be used to perform TCP/IP stack fingerprinting?
Select one option, then reveal solution.
Question No. 7
Which of the following Trojans is used by attackers to modify the Web browser settings?
Select one option, then reveal solution.
Question No. 8
Firewalking is a technique that can be used to gather information about a remote network protected
by a firewall. This technique can be used effectively to perform information gathering attacks. In this
technique, an attacker sends a crafted packet with a TTL value that is set to expire one hop past the
firewall. Which of the following are pre-requisites for an attacker to conduct firewalking?
Each correct answer represents a complete solution. Choose all that apply.
Select all that apply, then reveal solution.
Question No. 9
In which of the following steps of the incident handling processes does the Incident Handler make
sure that all business processes and functions are back to normal and then also wants to monitor the
system or processes to ensure that the system is not compromised again?
Select one option, then reveal solution.
Question No. 10
Which of the following languages are vulnerable to a buffer overflow attack?
Each correct answer represents a complete solution. Choose all that apply.
Select all that apply, then reveal solution.
Question No. 11
You want to add a netbus Trojan in the chess.exe game program so that you can gain remote access
to a friend's computer. Which of the following tools will you use to accomplish the task?
Each correct answer represents a complete solution. Choose all that apply.
Select all that apply, then reveal solution.
Question No. 12
Which of the following is an Internet mapping technique that relies on various BGP collectors that
collect information such as routing updates and tables and provide this information publicly?
Select one option, then reveal solution.
Question No. 13

Fill in the blank with the appropriate name of the attack. ______ takes best advantage of an existing authenticated connection

Question No. 14

Fill in the blank with the correct numeric value. ARP poisoning is achieved in ______ steps.

Select one option, then reveal solution.
Question No. 15

Fill in the blank with the appropriate term. ______ is a technique used to make sure that incoming packets are actually from the networks that they claim to be from.