GCIA Exam Questions
462 real GCIA exam questions with expert-verified answers and explanations. Page 2 of 10.
- Question #51Threat Intelligence & Network Security Monitoring
Which of the following is a reason to implement security logging on a DNS server?
DNS loggingzone transferDNS security monitoringunauthorized access - Question #52Intrusion Detection System (IDS) Fundamentals & Snort Rules
Which of the following is the process of categorizing attack alerts produced from an IDS in order to distinguish false positives from actual attacks?
alarm filteringIDS alert triagefalse positivesalert classification - Question #53Threat Intelligence & Network Security Monitoring
You work as a Network Security Administrator for NetPerfect Inc. The company has a Windowsbased network. You are incharge of the data and network security of the company. While per...
insider threatinternal threatthreat classificationdata exfiltration - Question #54Network Forensics, Protocol Insecurity & Evasion Techniques
John works as a professional Ethical Hacker. He has been assigned the project of testing the description of the tool is as follows: Which of the following tools is John using to cr...
AirSnortwireless encryption crackingWEPwireless attack tools - Question #55Network Forensics, Protocol Insecurity & Evasion Techniques
An attacker wants to launch an attack on a wired Ethernet. He wants to accomplish the following tasks: Sniff data frames on a local area network. Modify the network traffic. ...
ARP spoofingman-in-the-middleLAN attackstraffic manipulation - Question #56Packet Analysis with Wireshark & Command Line Tools
Which of the following utilities produces the output shown in the image below?
ping utilityICMPnetwork diagnosticscommand line output - Question #57Network Forensics, Protocol Insecurity & Evasion Techniques
An attacker changes the address of a sub-routine in such a manner that it begins to point to the address of the malicious code. As a result, when the function has been exited, the...
buffer overflowstack smashingreturn address hijackingSmashGuard - Question #58Intrusion Detection System (IDS) Fundamentals & Snort Rules
When no anomaly is present in an Intrusion Detection, but an alarm is generated, the response is known as __________.
false positiveIDS classificationdetection accuracyalarm types - Question #59Network Traffic Analysis & Protocol Review
Victor works as a professional Ethical Hacker for SecureEnet Inc. He wants to scan the wireless network of the company. He uses a tool that is a free open-source utility for networ...
Nmapnetwork scanningport scanningOS fingerprinting - Question #60Network Traffic Analysis & Protocol Review
Web applications are accessed by communicating over TCP ports via an IP address. Choose the two most common Web Application TCP ports and their respective protocol names. Each corr...
HTTPHTTPSTCP portsweb protocols - Question #61Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following statements about Secure Shell (SSH) are true? Each correct answer represents a complete solution. Choose three.
SSHsecure shellTELNET replacementencrypted channel - Question #62Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following utilities provides an efficient way to give specific users permission to use specific system commands at the root level of a Linux operating system?
SUDOLinux privilege managementroot accesssystem commands - Question #63Threat Intelligence & Network Security Monitoring
Adam, a novice Web user is getting large amount of unsolicited commercial emails on his email address. He suspects that the emails he is receiving are the Spam. Which of the follow...
spamemail securityFTC reportingISP abuse reporting - Question #64Network Traffic Analysis & Protocol Review
Which of the following protocols is used by voice over IP (VoIP) applications?
VoIPUDPtransport protocolreal-time communication - Question #65Packet Analysis with Wireshark & Command Line Tools
Which of the following tools can be used for passive OS fingerprinting?
passive OS fingerprintingtcpdumptraffic analysisreconnaissance - Question #66Network Traffic Analysis & Protocol Review
Which of the following utilities is used to display the current TCP/IP configuration of a Windows NT computer?
IPCONFIGWindows networkingTCP/IP configurationnetwork utilities - Question #67Intrusion Detection System (IDS) Fundamentals & Snort Rules
Which of the following would allow you to automatically close connections or restart a server or service when a DoS attack is detected?
active IDSautomated responseDoS detectionIDS response types - Question #68Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following is an asymmetric encryption algorithm?
asymmetric encryptionDiffie-Hellmancryptographykey exchange - Question #69Network Forensics, Protocol Insecurity & Evasion Techniques
Adam works as a professional Computer Hacking Forensic Investigator. He has been assigned with a project to investigate a computer in the network of SecureEnet Inc. The compromised...
Helix Livevolatile data collectiondigital forensicsforensic tools - Question #70Network Forensics, Protocol Insecurity & Evasion Techniques
Sandra, an expert computer user, hears five beeps while booting her computer that has AMI BIOS; and after that her computer stops responding. Sandra knows that during booting proce...
POST beep codesBIOS diagnosticshardware failureprocessor error - Question #71Network Forensics, Protocol Insecurity & Evasion Techniques
You work as a Network Administrator for McNeil Inc. The company has a TCP/IP-based network. You are configuring an Internet connection for your company. Your Internet service provi...
TELNETinsecure remote accessUNIX connectivityplaintext protocol - Question #72Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following tools works by using standard set of MS-DOS commands and can create an MD5 hash of an entire drive, partition, or selected files?
DriveSpyMD5 hashforensic imagingdrive acquisition - Question #73Network Traffic Analysis & Protocol Review
Which of the following firewalls operates at three layers- Layer3, Layer4, and Layer5?
dynamic packet-filtering firewallOSI layersfirewall typesstateful inspection - Question #74Intrusion Detection System (IDS) Fundamentals & Snort Rules
You work as a Network Administrator in a company. The NIDS is implemented on the network. You want to monitor network traffic. Which of the following modes will you configure on th...
promiscuous modeNIDSNIC configurationnetwork monitoring - Question #75Network Forensics, Protocol Insecurity & Evasion Techniques
Which of the following programs is used to add words to spam e-mails so that the e-mail is not considered spam and therefore is delivered as if it were a normal message?
hash busterspam evasionemail filter bypassanti-spam techniques - Question #76Network Traffic Analysis & Protocol Review
Which of the following is a valid IPv6 address?
IPv6IP addressingaddress formatnetwork addressing - Question #77Network Forensics, Protocol Insecurity & Evasion Techniques
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate computer of an unfaithful employee of SecureEnet Inc. Suspect...
Windows forensicsslack spaceswap filesdigital evidence collection - Question #78Threat Intelligence & Network Security Monitoring
You are responsible for security at a company that specializes in e-commerce. You realize that given the high volume of Web traffic, there is a significant chance of someone being...
honeypotdeception technologyperimeter securityattacker redirection - Question #79Network Traffic Analysis & Protocol Review
Which of the following Denial-of-Service (DoS) attacks employ IP fragmentation mechanism? Each correct answer represents a complete solution. Choose two.
IP fragmentationDoS attacksTeardropPing of Death - Question #80Network Traffic Analysis & Protocol Review
What are the advantages of stateless autoconfigration in IPv6? Each correct answer represents a part of the solution. Choose three.
IPv6stateless autoconfigurationSLAACaddress configuration - Question #81Network Traffic Analysis & Protocol Review
What are the advantages of an application layer firewall? Each correct answer represents a complete solution. Choose all that apply.
application layer firewallproxy firewalltraffic filteringDoS prevention - Question #82Network Forensics, Protocol Insecurity & Evasion Techniques
Victor works as a professional Ethical Hacker for SecureNet Inc. He wants to use Steganographic file system method to encrypt and hide some secret information. Which of the followi...
steganographyslack spacehidden partitiondata hiding - Question #83Network Forensics, Protocol Insecurity & Evasion Techniques
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate the main server of SecureEnet Inc. The server runs on Debian...
GRUBLinux bootforensic investigationconfiguration files - Question #84Network Traffic Analysis & Protocol Review
You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. A branch office is connected to the headquarters through a T1 line. Users at the b...
traffic shapingQoSbandwidth managementVoIP - Question #85Network Traffic Analysis & Protocol Review
Andrew works as an Administrator for a Windows 2000 based network. The network has a primary external DNS server, and a secondary DNS server located on the ISP's UNIX server, in or...
DNS zone transferBIND secondariessecondary DNSWindows DNS - Question #86Network Forensics, Protocol Insecurity & Evasion Techniques
Adam works on a Linux system. He is using Sendmail as the primary application to transmit e- mails. Linux uses Syslog to maintain logs of what has occurred on the system. Which of...
Syslogmail logsSendmailLinux logging - Question #87Network Traffic Analysis & Protocol Review
Which of the following statements are true about UDP? Each correct answer represents a complete solution. Choose all that apply.
UDPconnectionless protocolTFTPtransport layer - Question #88Network Traffic Analysis & Protocol Review
Ben works as a Network Administrator in Business Software Solutions Ltd. The company uses a Windowsbased operating system throughout its network. Ben finds the following mail excha...
DNS recordsA recordAAAA recordIPv4 IPv6 dual-stack - Question #89Network Traffic Analysis & Protocol Review
Which of the following IPv4 to IPv6 transition methods uses encapsulation of IPv6 packets to traverse IPv4 networks?
IPv6 tunnelingIPv4 to IPv6 transitionencapsulationprotocol transition - Question #90Intrusion Detection System (IDS) Fundamentals & Snort Rules
An IDS is a group of processes working together in a network. These processes work on different computers and devices across the network. Which of the following processes does an I...
IDS componentstraffic analysisanomaly detectionevent log analysis - Question #91Packet Analysis with Wireshark & Command Line Tools
Which of the following tools is used to detect round-robin-load-balancing?
tcptracerouteload balancing detectionround-robin DNSnetwork reconnaissance - Question #92Intrusion Detection System (IDS) Fundamentals & Snort Rules
Which of the following technologies is used to detect unauthorized attempts to access and manipulate computer systems locally or through the Internet or an intranet?
IDS definitionintrusion detectionunauthorized accessnetwork monitoring - Question #93Network Traffic Analysis & Protocol Review
Which of the following is the default port for Hypertext Transfer Protocol (HTTP)?
HTTPport 80well-known portsapplication protocols - Question #94Threat Intelligence & Network Security Monitoring
Which of the following is an example of penetration testing?
penetration testingethical hackingattack simulationsecurity assessment - Question #95Packet Analysis with Wireshark & Command Line Tools
John works as a professional Ethical Hacker for SecureEnet Inc. The company has a Windowsbased network. All client computers run on Windows XP. A project has been assigned to John...
netstatopen portsWindows CLIport enumeration - Question #96Network Forensics, Protocol Insecurity & Evasion Techniques
You are a professional Computer Hacking forensic investigator. You have been called to collect the evidences of Buffer Overflows or Cookie snooping attack. Which of the following l...
buffer overflowcookie snoopingforensic evidencelog analysis - Question #97Network Traffic Analysis & Protocol Review
Which of the following configuration schemes in IPv6 allows a client to automatically configure its own IP address with or without IPv6 routers?
IPv6stateless autoconfigurationSLAACaddress assignment - Question #98Threat Intelligence & Network Security Monitoring
John works as a Security Administrator for NetPerfect Inc. The company uses Windows-based systems. A project has been assigned to John to track malicious hackers and to strengthen...
honeypotdeception technologyattacker trackingdecoy systems - Question #99Network Traffic Analysis & Protocol Review
Adam, a malicious hacker is running a scan. Statistics of the scan is as follows: Which of the following types of port scan is Adam running?
FIN scanTCP flagsport scanningnetwork reconnaissance - Question #100Packet Analysis with Wireshark & Command Line Tools
Which of the following commands will you use with the tcpdump command to capture the traffic from a filter stored in a file?
tcpdumpBPF filterpacket capturecommand line tools