Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

GCIH - Book 5 Exam Questions And Answers Verified 100% Correct

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
16-06-2025
Written in
2024/2025

GCIH - Book 5 Exam Questions And Answers Verified 100% Correct The easiest way to hide files in UNIX is to name them... - ANSWER "." or ".." or " " other popular locations include: /dev /temp /etc In UNIX, main log files can be found by viewing... - ANSWER /etc/ Shell history is written when the shell is exited. Recent commands are stored in RAM until the shell is exited - ANSWER TRUE kill -9 [pid] - ANSWER killing the shell, so that it cannot write the most recent shell history killall -9 bash - ANSWER kill bash shells unset HISTFILE kill -9 $$ - ANSWER changing the enviornment HISTFILE utmp - ANSWER contains info about currently logged in users /var/run/utmp wtmp - ANSWER file contains data about past user logins /var/log/wtmp btmp - ANSWER file contains bad login entries for failed login attempts /var/log/btmp lastlog - ANSWER file shows login name, port and last login time for each user /var/log/lastlog to edit accounting files, an attacker must use a tool such as "remove" or "marry" - ANSWER TRUE File streaming applies only to NTFS partitions. It does not apply to FAT partitions - ANSWER True LADS - ANSWER a tool dedicated to finding alternate data streams in NTFS Streams - ANSWER a program that includes a very handy option for deleting a stream without impacting the host file By default in Windows, event logs are stored.... - ANSWER C:WindowsSystem32winevtLogs Three primary Windows event types are stored temporarily in the following log files: - ANSWER S At a minimum, to erase traces of activity, an attacker would have to edit BLANK - ANSWER S Each log file is periodically overwritten into a .evt format automatically, in the following files: - ANSWER Tunneling - ANSWER one protocol is carried inside another protocol i.e. carrying shell traffic inside ICMP packets ptunnel - ANSWER carries TCP connections over ICMP Echo and Reply packets) Loki - ANSWER carries shell between its linux client and linux server software using ICMP echo and Reply packets ICMPShell - ANSWER Linux shell tool Pingchat - ANSWER a windows chat program that uses ICMP ICMPCmd - ANSWER a windows shell tool using ICMP ptunnel consists of two components - ANSWER client and proxy Covert_TCP - ANSWER a tool that implements a covert channel using either the TCP or IP header Covert_TCP allows for transmitting information by entering ASCII in the following TCP/IP header fields - ANSWER IP identification TCP initial sequence number TCP acknowledgment sequence number

Show more Read less
Institution
GCIH - Book 5
Course
GCIH - Book 5

Content preview

GCIH - Book 5 Exam Questions And Answers
Verified 100% Correct

The easiest way to hide files in UNIX is to name them... - ANSWER "." or ".." or " "

other popular locations include:
/dev
/temp
/etc

In UNIX, main log files can be found by viewing... - ANSWER /etc/sysog.conf
Shell history is written when the shell is exited. Recent commands are stored in RAM
until the shell is exited - ANSWER TRUE

kill -9 [pid] - ANSWER killing the shell, so that it cannot write the most recent shell
history

killall -9 bash - ANSWER kill bash shells

unset HISTFILE
kill -9 $$ - ANSWER changing the enviornment HISTFILE

utmp - ANSWER contains info about currently logged in users
/var/run/utmp

wtmp - ANSWER file contains data about past user logins
/var/log/wtmp

btmp - ANSWER file contains bad login entries for failed login attempts
/var/log/btmp

lastlog - ANSWER file shows login name, port and last login time for each user
/var/log/lastlog

to edit accounting files, an attacker must use a tool such as "remove" or "marry" -
ANSWER TRUE

File streaming applies only to NTFS partitions. It does not apply to FAT partitions -
ANSWER True

LADS - ANSWER a tool dedicated to finding alternate data streams in NTFS

, Streams - ANSWER a program that includes a very handy option for deleting a stream
without impacting the host file

By default in Windows, event logs are stored.... - ANSWER
C:\Windows\System32\winevt\Logs

Three primary Windows event types are stored temporarily in the following log files: -
ANSWER System.log
security.log
application.log

At a minimum, to erase traces of activity, an attacker would have to edit
BLANK -
ANSWER
Secevent.evt
Each log file is periodically overwritten into a .evt format automatically, in the
following
files: - ANSWER
sysevent.evtx
secevent.evtx
appevent.evtx

Tunneling - ANSWER one protocol is carried inside another protocol
i.e. carrying shell traffic inside ICMP packets

ptunnel - ANSWER carries TCP connections over ICMP Echo and Reply packets)

Loki - ANSWER carries shell between its linux client and linux server software using
ICMP echo and Reply packets

ICMPShell - ANSWER Linux shell tool

Pingchat - ANSWER a windows chat program that uses ICMP

ICMPCmd - ANSWER a windows shell tool using ICMP

ptunnel consists of two components - ANSWER client and proxy

Covert_TCP - ANSWER a tool that implements a covert channel using either the TCP
or IP header

Covert_TCP allows for transmitting information by entering ASCII in the following
TCP/IP header fields - ANSWER IP identification
TCP initial sequence number
TCP acknowledgment sequence number

Written for

Institution
GCIH - Book 5
Course
GCIH - Book 5

Document information

Uploaded on
June 16, 2025
Number of pages
6
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$9.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeGuru Teachme2-tutor
Follow You need to be logged in order to follow users or courses
Sold
15
Member since
1 year
Number of followers
0
Documents
2395
Last sold
2 months ago
GRADEHUB

We provide access to a wide range of professionally curated exams for students and educators. It offers high-quality, up-to-date assessment materials tailored to various subjects and academic levels. With instant downloads and affordable pricing, it\'s the go-to resource for exam preparation and academic success.

1.5

2 reviews

5
0
4
0
3
0
2
1
1
1

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions