Want to pass your GIAC Certified Incident Handler (GCIH) GCIH exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
Which of the following is ALWAYS a good guideline for incident response processes?
A. Information regarding the incident should be provided to anyone who asks
B. Require the incident handler to work alone in order to preserve evidence integrity
C. Information regarding the incident should only be known by the primary incident responder
D. If resources allow, assign a helper to the primary incident responder
What is the result of unloading a process' forward and backwards links in memory?
A. The process is hidden from the operating system
B. Analysis tools cannot find the process when scanning memory
C. The process owner is elevated to SYSTEM permissions
D. The application crashes
When probing for command injection opportunities on a remote host, why would an attacker target her own address space from the remote host?
A. Collection of URL session tokens
B. Legal requirement
C. Verification of a blind attack
D. Detect target's operating system