nerdexam
GIAC

GCIH · Question #378

As an incident handler for the xyz widget company, you have responded to the breach of your mail server. The server is not in a DMZ but on your internal network and was being used as a launching…

The correct answer is C. dd. The second sub phase is backup. Of the listed tools only dd can be used to create a backup of the compromised hard drive. Cain and Enum are tools used to attack systems and Wireshark is a network sniffer.

Incident Response & Cyber Kill Chain

Question

As an incident handler for the xyz widget company, you have responded to the breach of your mail server. The server is not in a DMZ but on your internal network and was being used as a launching point to attack other systems on the same network. The compromise was discovered quickly and the network cable was disconnected from the mail server. Which of the following tools will allow you to complete the next sub phase, following short-term containment activities, on the server in its current state?

Options

  • AWireshark
  • BEnum
  • Cdd
  • DCain

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    10% (5)
  • C
    81% (39)
  • D
    2% (1)

Explanation

The second sub phase is backup. Of the listed tools only dd can be used to create a backup of the compromised hard drive. Cain and Enum are tools used to attack systems and Wireshark is a network sniffer.

Topics

#forensic imaging#dd tool#evidence collection#containment sub-phases

Community Discussion

No community discussion yet for this question.

Full GCIH Practice