GIAC Certified Enterprise Defender - GCED Exam Practice Test

When attempting to collect data from a suspected system compromise, which of the following should generally be collected first?

Correct Answer: B Vote an answer
You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexplorer.exe and iexplorer.sys. Based on the behavior of the system you suspect that these files are part of a rootkit. If this is the case what is the likely purpose of the .sys file?

Correct Answer: B Vote an answer
What feature of Wireshark allows the analysis of one HTTP conversation?

Correct Answer: D Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
Why would an incident handler acquire memory on a system being investigated?

Correct Answer: C Vote an answer
Why would a Cisco network device with the latest updates and patches have the service config setting enabled, making the device vulnerable to the TFTP Server Attack?

Correct Answer: B Vote an answer
Explanation: Only visible for Fast2test members. You can sign-up / login (it's free).
What would be the output of the following Google search?
filetype:doc inurl:ws_ftp

Correct Answer: B Vote an answer
Which of the following is an SNMPv3 security feature that was not provided by earlier versions of the protocol?

Correct Answer: B Vote an answer
Which tool uses a Snort rules file for input and by design triggers Snort alerts?

Correct Answer: D Vote an answer
Which of the following is the best way to establish and verify the integrity of a file before copying it during an investigation?

Correct Answer: D Vote an answer

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 ) From Monday to Saturday

Support: Contact now 

日本語 Deutsch 繁体中文 한국어