GCIA Exam Questions
462 real GCIA exam questions with expert-verified answers and explanations. Page 1 of 10.
- Question #1Advanced Incident Response & Digital Forensics Fundamentals
You are the Network Administrator for a large corporate network. You want to monitor all network traffic on your local network for suspicious activities and receive a notification...
IDSnetwork monitoringintrusion detectionNIDS - Question #2Advanced Windows Artifacts & Browser Forensics
Adam works as a professional Computer Hacking Forensic Investigator. He wants to investigate a suspicious email that is sent using a Microsoft Exchange server. Which of the followi...
Exchange serveremail forensicsEDB filescheckpoint files - Question #3Memory Forensics & Anti-Forensics Detection
Victor wants to send an encrypted message to his friend. He is using certain steganography technique to accomplish this task. He takes a cover object and changes it accordingly to...
steganographydistortion techniquedata hidingcover object - Question #4Threat Hunting & Timeline Analysis
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple smallsized packets to the target computer. Hence, it becomes very difficult for an IDS t...
session splicingIDS evasionpacket fragmentationnetwork evasion - Question #5Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. You want to know the current TCP/IP network configuration settings, DHCP server IP...
IPCONFIGDHCPTCP/IP configurationnetwork utilities - Question #6Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server2008 network environment. The network is configured as a Windows Active Directory- based si...
NIC failureloopback diagnosticIPv6 networkinghardware troubleshooting - Question #7Advanced Incident Response & Digital Forensics Fundamentals
John, a malicious hacker, forces a router to stop forwarding packets by flooding it with many open connections simultaneously so that all hosts behind it are effectively disabled....
DoS attackrouter floodingconnection exhaustionnetwork attack - Question #8Advanced Incident Response & Digital Forensics Fundamentals
John works as a Network Security Administrator for NetPerfect Inc. The manager of the company has told John that the company's phone bill has increased drastically. John suspects t...
phreakingtelecommunications attackphone systemsocial engineering - Question #9Threat Hunting & Timeline Analysis
You are implementing a host based intrusion detection system on your web server. You feel that the best way to monitor the web server is to find your baseline of activity (connecti...
anomaly-based IDSbaseline monitoringbehavioral analysisintrusion detection - Question #10Advanced Incident Response & Digital Forensics Fundamentals
Which of the following is the default port for POP3?
POP3port 110email protocolswell-known ports - Question #11Advanced Incident Response & Digital Forensics Fundamentals
You work as a network administrator for BlueWell Inc. You have to convert your 48-bit host address (MAC address) to an IPv6 54-bit address. Using the IEEE-EUI-64 conversion process...
EUI-64IPv6 addressingMAC address conversionnetwork addressing - Question #12Advanced Incident Response & Digital Forensics Fundamentals
Which of the following units of data does the data-link layer send from the network layer to the physical layer of the OSI model?
OSI modeldata-link layerdata framesnetwork layers - Question #13Advanced Incident Response & Digital Forensics Fundamentals
The following output is generated by running the show ip route command: RouterA#show ip route < - - Output Omitted for brevity - -> Which next hop address will RouterA use in forwa...
IP routingrouting tablenext hoproute selection - Question #14Advanced Incident Response & Digital Forensics Fundamentals
Which of the following types of firewall ensures that the packets are part of the established session?
stateful inspectionfirewallsession trackingpacket filtering - Question #15Threat Hunting & Timeline Analysis
Which of the following terms describes an attempt to transfer DNS zone data?
DNS zone transferreconnaissanceAXFRinformation gathering - Question #16Advanced Incident Response & Digital Forensics Fundamentals
You work as a Network Administrator for McRobert Inc. Your company has a TCP/IP-based network. You want to get the protocol statistics and the active TCP/IP network connections of...
NETSTATTCP connectionsnetwork statisticsactive connections - Question #17Advanced Windows Artifacts & Browser Forensics
What are the limitations of the POP3 protocol? Each correct answer represents a complete solution. Choose three.
POP3email protocolprotocol limitationsemail retrieval - Question #18Advanced Incident Response & Digital Forensics Fundamentals
What is the order of the extension headers that is followed by IPv6?
IPv6extension headerspacket structureheader ordering - Question #19Network Traffic Analysis & Protocol Review
Which of the following statements about FTP is true?
FTPfile transfer protocolapplication layer protocols - Question #20Network Forensics, Protocol Insecurity & Evasion Techniques
Rick works as a Computer Forensic Investigator for BlueWells Inc. He has been informed that some confidential information is being leaked out by an employee of the company. Rick su...
steganographytext semagramslinguistic steganographydata exfiltration - Question #21Advanced Snort Rule Writing & Signature Evasion
John works as a professional Ethical Hacker. He has been assigned the project of testing the that one packet fragment overlaps data from a previous fragment so that he can perform...
fragment overlapIDS evasionMendaxpacket fragmentation - Question #22Intrusion Detection System (IDS) Fundamentals & Snort Rules
In which of the following IDS evasion techniques does an attacker deliver data in multiple small sized packets, which makes it very difficult for an IDS to detect the attack signat...
session splicingIDS evasionsmall packet attacksignature bypass - Question #23Network Forensics, Protocol Insecurity & Evasion Techniques
Peter works as a professional Computer Hacking Forensic Investigator for eLaw-Suit law firm. He is working on a case of a cyber crime. Peter knows that the good investigative repor...
lay witnessforensic investigationexpert witnesslegal testimony - Question #24Packet Analysis with Wireshark & Command Line Tools
You work as a network administrator for Tech Perfect Inc. Rick, your assistant, requires information regarding his computer's IP address lease start date and expiry date. Which of...
ipconfigDHCP leasecommand line toolsIP configuration - Question #25Network Traffic Analysis & Protocol Review
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008- based network. You have created a test domain for testing IPv6 addressing. Which of...
IPv6 address typesunicastmulticastanycast - Question #26Advanced Snort Rule Writing & Signature Evasion
John works as a professional Ethical Hacker. He has been assigned a project for testing the performing attacks on the server is made easy and he can observe the flaws in the We-are...
polymorphic shellcodeIDS evasionsignature mutationmalware detection bypass - Question #27Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following is the correct order of loading system files into the main memory of the system, when the computer is running on Microsoft's Windows XP operating system?
Windows XP boot sequenceNTLDROS forensicssystem files - Question #28Network Forensics, Protocol Insecurity & Evasion Techniques
By gaining full control of router, hackers often acquire full control of the network. Which of the following methods are commonly used to attack Routers? Each correct answer repres...
router attacksroute table poisoningnetwork infrastructure attacksrouter security - Question #29Network Traffic Analysis & Protocol Review
Which of the following is a valid IP address for class B Networks?
IP address classesclass B addressingIPv4 rangessubnetting - Question #30Network Forensics, Protocol Insecurity & Evasion Techniques
Trinity wants to send an email to her friend. She uses the MD5 generator to calculate cryptographic hash of her email to ensure the security and integrity of the email. MD5 generat...
MD5 hashcryptographic integritychecksum verificationemail security - Question #31Network Traffic Analysis & Protocol Review
Distributed Checksum Clearinghouse (DCC) is a hash sharing method of spam email detection. Which of the following protocols does the DCC use?
DCC spam detectionUDP protocolhash sharingspam filtering - Question #32Network Traffic Analysis & Protocol Review
Which of the following proxy servers is placed anonymously between the client and remote server and handles all of the traffic from the client?
proxy server typesforced proxyanonymous proxytraffic interception - Question #33Intrusion Detection System (IDS) Fundamentals & Snort Rules
You work as a Network Administrator for SmartCert Inc. The company's network contains five Windows 2003 servers and ninety Windows XP Professional client computers. You want to vie...
URLScanIIS filteringintrusion detectionHTTP request inspection - Question #34Network Traffic Analysis & Protocol Review
Adam, a malicious hacker purposely sends fragmented ICMP packets to a remote target. The total size of this ICMP packet once reconstructed is over 65,536 bytes. On the basis of abo...
ping of deathICMP fragmentationoversized packetsDoS attack - Question #35Packet Analysis with Wireshark & Command Line Tools
You work as a Computer Hacking Forensic Investigator for SecureNet Inc. You want to investigate Cross-Site Scripting attack on your company's Website. Which of the following method...
XSS investigationweb proxy analysisWiresharkweb server logs - Question #36Network Forensics, Protocol Insecurity & Evasion Techniques
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate Plagiarism occurred in the source code files of C#. Which of th...
software plagiarismJplagsource code forensicsforensic tools - Question #37Network Traffic Analysis & Protocol Review
Which of the following IPv6 transition technologies is used by the DirectAccess if a user is in a remote location and a public IPv4 address, instead of public IPv6 address, has bee...
IPv6 transition6to4DirectAccesstunneling technology - Question #38Network Forensics, Protocol Insecurity & Evasion Techniques
Maria works as the Chief Security Officer for passguide Inc. She wants to send secret messages to the CEO of the company. To secure these messages, she uses a technique of hiding a...
steganographysecurity through obscurityhidden messagescovert communication - Question #39Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following is allowed by a company to be addressed directly from the public network and is hardened to screen the rest of its network from security exposure?
bastion hostnetwork hardeningperimeter securityDMZ - Question #40Packet Analysis with Wireshark & Command Line Tools
You work as a technician for Tech Perfect Inc. You are troubleshooting an Internet name resolution issue. You ping your ISP's DNS server address and find that the server is down. Y...
ping commandcontinuous pingnetwork troubleshootingCLI switches - Question #41Network Traffic Analysis & Protocol Review
In a complex network, Router transfers data packets by observing some form of parameters or metrics provided in the routing table. Which of the following metrics is NOT included in...
routing tablerouting metricsbandwidthnetwork routing - Question #42Network Traffic Analysis & Protocol Review
What is the easiest way to verify that name resolution is functioning properly on a TCP/IP network?
DNS resolutionname resolutionTCP/IP troubleshootingping - Question #43Packet Analysis with Wireshark & Command Line Tools
Which of the following tools is an open source protocol analyzer that can capture traffic in real time?
Wiresharkprotocol analyzerpacket captureopen source tools - Question #44Network Traffic Analysis & Protocol Review
Which of the following types of firewall functions by creating two different communications, one between the client and the firewall, and the other between the firewall and the end...
proxy firewallfirewall typesapplication-layer filteringconnection proxying - Question #45Packet Analysis with Wireshark & Command Line Tools
Adam, an expert computer user, doubts that virus named love.exe has attacked his computer. This virus acquires hidden and read-only attributes, so it is difficult to delete it. Ada...
del commandfile attributeshidden filesWindows CLI - Question #46Network Traffic Analysis & Protocol Review
Which of the following is the primary TCP/IP protocol used to transfer text and binary files over the Internet?
FTPfile transfer protocolTCP/IP protocolsapplication layer - Question #47Network Forensics, Protocol Insecurity & Evasion Techniques
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate and examine drive image of a compromised system, which is sus...
digital forensicsdisk image formatsforensic toolsevidence acquisition - Question #48Threat Intelligence & Network Security Monitoring
You are planning DNS configuration for your company. You decide to configure an Active Directory integrated DNS. Which of the following are the benefits of Active Directory integra...
Active Directory DNSDNS replicationmulti-master DNSDNS security - Question #49Network Traffic Analysis & Protocol Review
Adam works as a Network Administrator for passguide Inc. He wants to prevent the network from DOS attacks. Which of the following is most useful against DOS attacks?
DoS defensestateful packet inspectionSPIfirewall countermeasures - Question #50Packet Analysis with Wireshark & Command Line Tools
You work as a Network Administrator of a TCP/IP network. You are having DNS resolution problem. Which of the following utilities will you use to diagnose the problem?
NSLOOKUPDNS troubleshootingDNS resolutionnetwork utilities