GCIH 試験対策書 & GIAC Certified Incident Handler


NO.1 You work as a Network Administrator for Net Perfect Inc. The company has a Windows-based
network. The company
wants to fix potential vulnerabilities existing on the tested systems. You use Nessus as a vulnerability
program to fix the vulnerabilities. Which of the following vulnerabilities can be fixed using Nessus?
Each correct answer represents a complete solution. Choose all that apply.
A. Vulnerabilities that allow a remote cracker to access sensitive data on a system
B. Vulnerabilities that allow a remote cracker to control sensitive data on a system
C. Misconfiguration (e.g. open mail relay, missing patches, etc.)
D. Vulnerabilities that help in Code injection attacks
Answer: A,B,C

NO.2 The IT administrator wants to implement a stronger security policy. What are the four most
important security
priorities for PassGuide Software Systems Pvt. Ltd.?
(Click the Exhibit button on the toolbar to see the case study.)
A. Ensuring secure authentication.
B. Preventing denial-of-service attacks.
C. Preventing unauthorized network access.
D. Providing secure communications between the overseas office and the headquarters.
E. Providing secure communications between Washington and the headquarters office.
F. Providing two-factor authentication.
G. Implementing Certificate services on Texas office.
H. Protecting employee data on portable computers.
Answer: A,C,D,H

NO.3 Which of the following commands is used to access Windows resources from Linux
A. scp
B. smbclient
C. mutt
D. rsync
Answer: B

NO.4 A Denial-of-Service (DoS) attack is mounted with the objective of causing a negative impact on
the performance of a
computer or network. It is also known as network saturation attack or bandwidth consumption
attack. Attackers
perform DoS attacks by sending a large number of protocol packets to a network. The problems
caused by a DoS
attack are as follows:
* Saturation of network resources
* Disruption of connections between two computers, thereby preventing communications between
* Disruption of services to a specific computer
* Failure to access a Web site
* Increase in the amount of spam
Which of the following can be used as countermeasures against DoS attacks?
Each correct answer represents a complete solution. Choose all that apply.
A. Blocking undesired IP addresses
B. Permitting network access only to desired traffic
C. Disabling unneeded network services
D. Applying router filtering
Answer: A,B,C,D

