Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

SANS GCIH (SEC504) EXAM 100 QUESTIONS AND ANSWERS NEWEST 2026 100% PASS

Beoordeling
-
Verkocht
-
Pagina's
37
Cijfer
A+
Geüpload op
04-02-2026
Geschreven in
2025/2026

SANS GCIH (SEC504) EXAM 100 QUESTIONS AND ANSWERS NEWEST 2026 100% PASS SANS GCIH (SEC504) EXAM 100 QUESTIONS AND ANSWERS NEWEST 2026 100% PASS SANS GCIH (SEC504) EXAM 100 QUESTIONS AND ANSWERS NEWEST 2026 100% PASS

Instelling
Vak

Voorbeeld van de inhoud

SANS GCIH (SEC504) EXAM 100 QUESTIONS AND
ANSWERS NEWEST 2026 100% PASS
Who should make the decision of when to put a system back into production?


A) Systems administrators
B) Business team
C) Security team
D) Data owner - ANSWER---B) Business team


Which command will display ASCII and Unicode strings within a malware sample?


A) cat
B) Get-Strings
C) strings
D) findstr - ANSWER---C) strings


Which type of system is most commonly used to investigate malware?


A) Virtual machine
B) Day-to-day host
C) Thick client
D) Production system - ANSWER---A) Virtual machine


If you believe your system has been the victim of a rootkit attack, what is the most cost-
effective form of eradication?


A) Restore the OS from the most recent backup.
B) Reformat, reinstall, and patch the system from the original media.
C) Patch and reboot the compromised system.

, SANS GCIH (SEC504) EXAM 100 QUESTIONS AND
ANSWERS NEWEST 2026 100% PASS
D) Install applications from a different vendor. - ANSWER---B) Reformat, reinstall, and
patch the system from the original media.


What tool is used to record the state of the registry before and after malware is
executed on an analysis system?


A) Regshot
B) Ollydbg
C) Wireshark
D) Regripper - ANSWER---A) Regshot


What method could be used to ensure that an asset under investigation is not put back
into production without approval before the investigation is complete?


A) Move the asset to a different cloud data center.
B) Terminate the asset.
C) Shut off all administrative access to the cloud environment so no admins can make
changes.
D) Add an "under investigation" tag to the asset. - ANSWER---D) Add an "under
investigation" tag to the asset.


During the remediation phase of incident response, you remove a file from your infected
web server. What is the most important additional thing to do to prevent being
compromised again?


A) Determine the root cause of the attack.
B) Review your host-based firewall rules.
C) Restore the host data from backups.
D) Apply patches and harden the system. - ANSWER---A) Determine the root cause of
the attack.

, SANS GCIH (SEC504) EXAM 100 QUESTIONS AND
ANSWERS NEWEST 2026 100% PASS

Why is performing memory analysis on RAM images a staple of investigations?


A) Valuable information may exist in RAM, which might not be found on disk.
B) Speed - Evidence from a RAM image will match disk content.
C) RAM provides more consistent images than disk.
D) It's easier to look for historical information in RAM than on disk. - ANSWER---A)
Valuable information may exist in RAM, which might not be found on disk.


An investigator identifies the following POST request. Which log recorded the activity?


1583050850.951 185 192.168.40.123 TCP_MISS/200 1856 POST
https://update.googleapis.com/service/update2? -ORIGINAL_DST/172.219.10.153
text/xml


A) Switch access log
B) Regshot event log
C) Proxy access log
D) Windows event log - ANSWER---C) Proxy access log


What are two basic approaches commonly employed when investigating malware?


A) Running a penetration test and running a vulnerability scan.
B) Monitoring the environment and examining code.
C) Taking the environment offline and restoring from backups.
D) Performing a risk assessment and confirming a possible exploit type. - ANSWER---
B) Monitoring the environment and examining code.

, SANS GCIH (SEC504) EXAM 100 QUESTIONS AND
ANSWERS NEWEST 2026 100% PASS
What step should always be taken first during an incident?


A) Identifying which systems are unpatched.
B) Verifying whether an incident occurred.
C) Determining which threat intelligence feeds to query.
D) Choosing which systems to rebuild. - ANSWER---B) Verifying whether an incident
occurred.


In what way is logging API access to a cloud environment a major incident response
benefit?


A) It helps to provide detailed insight into network activity for analysis.
B) It helps to understand the scope of the breach and the actions taken by an
attacker.
C) It provides verification of breached data access.
D) It provides full packet capture visibility. - ANSWER---B) It helps to understand the
scope of the breach and the actions taken by an attacker.


API access logs include all programmatic access to cloud services, identity and key
use, and a record of attacker tactics used to exploit the cloud. These are the most
useful data for understanding the scope of a breach and the actions taken by the
attacker.


In a packet capture, an analyst observes that a system sent a frequent, small, outbound
communication to a known bad IP, over a seven-day period. What type of behavior is
possibly occurring?


A) Ack scan
B) Fragmentation
C) Beaconing

Geschreven voor

Vak

Documentinformatie

Geüpload op
4 februari 2026
Aantal pagina's
37
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$26.47
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
ERICPinchus Walden University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
159
Lid sinds
3 jaar
Aantal volgers
85
Documenten
2437
Laatst verkocht
4 weken geleden
Perfect Expert Scores

Welcome to my all inclusive store. Get all quality study materials at a cost-effective price. Hello! I'm Prof Eric, and I specialize in a diverse range of subjects including Health Care, Nursing, History, Mathematics, Psychology, and Biology. With a commitment to academic excellence, my work includes meticulously updated exam solutions and study materials designed to help you succeed. Why Choose My Documents: 1.Expertise Across Disciplines: Whether you need help with complex biology concepts, nursing fundamentals, historical analysis, mathematical problems, psychological theories, or healthcare insights, I've got you covered. 2.Updated Exam Solutions: My materials are regularly refreshed to ensure you have the most current and relevant information for your exams. 3.Detailed and Clear: Each document is crafted with precision to provide clarity and ease of understanding, making your study sessions more productive. Welcome to my all inclusive store.Get all quality study materials at a cost-effective price EXCELLENT HOMEWORK HELP AND TUTORING ,ALL KIND OF QUIZ AND EXAMS WITH GUARANTEE OF A. I ensure scholarly standards in my documents and that's why i'm one of the BEST GOLD RATED TUTORS in Stuvia. I assure a GOOD GRADE if you will use my work.

Lees meer Lees minder
4.6

317 beoordelingen

5
223
4
65
3
20
2
5
1
4

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen