Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

LATEST GCIH EXAM WITH 100% SOLUTION

Rating
-
Sold
-
Pages
18
Uploaded on
30-01-2024
Written in
2023/2024

What people should be brought in as an incident response team? - ANSWER * Security * Systems Admin * Network Management * Legal * HR * Public Affairs * Disaster Recovery * Union Rep How should the incident response team be organized? - ANSWER With onsite people Establish a baseline for response What are some ways to prepare for issues? - ANSWER * System build checklists per system type * Establish comp time for the team - What should go into an emergency communications plan? - ANSWER * Create a call list and establish methods of informing people quickly * Get a conference bridge number that can be set up * Print credit-card sized list of incident response team contact info * Testing to verify people answer the phone What should a war room contain? - ANSWER * Locking door * Locking file cabinet * No windows What are the main training issues when training an incident response team? - ANSWER * Creating forensics images under fire * keyboard skills under fire What should go into a jump bag? - ANSWER * Binary image creation software: dd, windd, netcat * forensic software * Diagnosis software * Bootable media * USB Token RAM Device * External Hard drive * Ethernet Tap * Patch Cables * Laptop with Multiple OS * Call list * anti-static plastic bags * Desiccants for moisture * Notebooks * Jumpers * Flashlight * Screwdrivers * female to female RJ-45 What is the goal of the identification phase? - ANSWER * gather events, analyze them, determine whether or not there is an incident What are some trends in the underground community? - ANSWER * Attack tools getting easier to use * High-quality, extremely functional tools * Rise of the anti-disclosure movement * Rise of hacktivism What are software distro site attacks? - ANSWER * Software on a repository is hacked into and software is altered to include a back door. * ISR-Evilgrade listens to software to request update * sends response with malware * Currently supports Java, Winzip, WinAmp, OSX, OpenOffice, itunes, etc Software distro site defenses - ANSWER * Check hashes across multiple mirrors - check both MD5 and SHA-1 * Check PGP signatures if available - be sure the key is trustworthy * Test software before putting it in production What are some general trends in attacking? - ANSWER * Worms are increasingly being used to carry bots, backdoors, password crackers, and scanners * Botnets are growing with self replicating code * Distributed co-op attackers are very popular What is reconnaissance? - ANSWER * Basically casing the joint * generally script kiddies or people out to get a specific site * gathering as much information as possible from open sources What information can be gathered from domain name registration? - ANSWER * Address * Phone numbers * Points of contact * authoritative domain name servers How can WHOIS be used for research? - ANSWER * can gather contact names, DNS information * has information on registrar * has information on IP blocks owned by the registrar Whois recon defenses - ANSWER * Preparation - Just live with it, because that's the internet - have real contact information with up to date records * Identification - can't really tell that anyone has looked you up What is a DNS zone transfer? - ANSWER * dumps all records from DNS servers and can show the attacker which machines are accessible on the internet How is a zone transfer done in Windows? - ANSWER nslookup server authoritative server IP or name set type=any ls -d target domain How is a zone transfer done in Unix? - ANSWER dig @DNS server IP target domain -t AXFR What are DNS recon defenses? - ANSWER * Preparation - do not allow zone transfers from just any system - limit zone transfers so primary accepts these requests only by secondary and tertiary servers - use split DNS - external name info in external server - internal name info in internal servers - make sure DNS servers are hardened * Identification - Look for zone transfers in logs from port 53 What sites can be used for reconnaissance? - ANSWER * target's own sites * press releases * white papers * design documents * sample deliverables * open positions * key people

Show more Read less
Institution
GCIH
Course
GCIH










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
GCIH
Course
GCIH

Document information

Uploaded on
January 30, 2024
Number of pages
18
Written in
2023/2024
Type
Exam (elaborations)
Contains
Unknown

Subjects

$14.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
contenthive76 Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
65
Member since
2 year
Number of followers
34
Documents
1929
Last sold
3 months ago

2.8

5 reviews

5
1
4
1
3
1
2
0
1
2

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions