Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the SANS Certified Incident Handler SEC504 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam SEC504 Premium Access

View all detail and faqs for the SEC504 exam


794 Students Passed

94% Average Score

92% Same Questions
Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions
Questions # 21:

You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?

Options:

A.

Containment

B.

Preparation

C.

Recovery

D.

Identification

Questions # 22:

Which of the following rootkits adds additional code or replaces portions of an operating system, including both the kernel and associated device drivers?

Options:

A.

Hypervisor rootkit

B.

Boot loader rootkit

C.

Kernel level rootkit

D.

Library rootkit

Questions # 23:

Which of the following tools is described in the statement given below?

"It has a database containing signatures to be able to detect hundreds of vulnerabilities in UNIX, Windows, and commonly used web CGI scripts. Moreover, the database detects DdoS zombies and Trojans as well."

Options:

A.

SARA

B.

Nessus

C.

Anti-x

D.

Nmap

Questions # 24:

Which of the following statements are correct about spoofing and session hijacking?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target and the valid user cannot be active.

B.

Spoofing is an attack in which an attacker can spoof the IP address or other identity of the target but the valid user can be active.

C.

Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is disconnected.

D.

Session hijacking is an attack in which an attacker takes over the session, and the valid user's session is not disconnected.

Questions # 25:

Your IDS discovers that an intruder has gained access to your system. You immediately stop that access, change passwords for administrative accounts, and secure your network. You discover an odd account (not administrative) that has permission to remotely access the network. What is this most likely?

Options:

A.

An example of privilege escalation.

B.

A normal account you simply did not notice before. Large networks have a number of accounts; it is hard to track them all.

C.

A backdoor the intruder created so that he can re-enter the network.

D.

An example of IP spoofing.

Questions # 26:

John works as a professional Ethical Hacker. He is assigned a project to test the security of www.weare- secure.com. He enters a single quote in the input field of the login page of the We-are-secure Web site and receives the following error message:

Microsoft OLE DB Provider for ODBC Drivers error '0x80040E14'

This error message shows that the We-are-secure Website is vulnerable to __________.

Options:

A.

A buffer overflow

B.

A Denial-of-Service attack

C.

A SQL injection attack

D.

An XSS attack

Questions # 27:

Which of the following types of attacks come under the category of hacker attacks?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Smurf

B.

IP address spoofing

C.

Teardrop

D.

Password cracking

Questions # 28:

Peter works as a Network Administrator for the PassGuide Inc. The company has a Windows-based network. All client computers run the Windows XP operating system. The employees of the company complain that suddenly all of the client computers have started working slowly. Peter finds that a malicious hacker is attempting to slow down the computers by flooding the network with a large number of requests. Which of the following attacks is being implemented by the malicious hacker?

Options:

A.

SQL injection attack

B.

Denial-of-Service (DoS) attack

C.

Man-in-the-middle attack

D.

Buffer overflow attack

Questions # 29:

Which of the following languages are vulnerable to a buffer overflow attack?

Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

Java

B.

C++

C.

C

D.

Action script

Questions # 30:

Which of the following types of attacks slows down or stops a server by overloading it with requests?

Options:

A.

DoS attack

B.

Impersonation attack

C.

Network attack

D.

Vulnerability attack

Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.