Exploitation and Privilege Escalation for GIAC Certified Incident Handler (GCIH)

This page covers the Exploitation and Privilege Escalation domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 20 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Which of the following types of attacks is the result of vulnerabilities in a program due to poor programming techniques?
    1. A. Evasion attack
    2. B. Denial-of-Service (DoS) attack
    3. C. Ping of death attack
    4. D. Buffer overflow attack
    Explanation

    The correct answer is: D. Buffer overflow attack.

    A buffer overflow attack is the direct result of poor programming technique: the developer copies input into a fixed-size region without checking that it fits, and an attacker supplies more data than the region can hold. The surplus lands in adjacent memory, and if it reaches a saved return address the attacker can choose where execution resumes. This is why the defect is so closely tied to coding practice, and why the remedy is bounds-checked copying, safer library functions, and compiler and operating system protections rather than anything at the network layer. The other options are not caused by programming flaws in the target. An evasion attack manipulates how traffic is presented so that a monitoring device and the destination host interpret it differently. A denial of service aims at exhausting a resource. A ping of death relies on malformed oversized packets and is a specific denial of service technique rather than a general consequence of poor coding.

  2. Question 2

    John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He finds that the We-are- secure server is vulnerable to attacks. As a countermeasure, he suggests that the Network Administrator should remove the IPP printing capability from the server. He is suggesting this as a countermeasure against __________.
    1. A. IIS buffer overflow
    2. B. NetBIOS NULL session
    3. C. SNMP enumeration
    4. D. DNS zone transfer
    Explanation

    The correct answer is: A. IIS buffer overflow.

    Internet Printing Protocol support in older versions of Internet Information Services was implemented as an extension that contained a buffer overflow: an oversized value in a request could overrun a fixed buffer and give an attacker code execution in the context of the web service. Because printing over the web is a function very few internet-facing servers actually need, removing the printing capability eliminates the exposed code path entirely rather than merely filtering input to it, which makes it a textbook countermeasure against that overflow. The other options describe unrelated exposures. A NetBIOS null session is an anonymous connection to the interprocess communication share, addressed by restricting anonymous enumeration. SNMP enumeration is countered by removing default community strings or disabling the service. A DNS zone transfer is prevented by restricting transfers to authorised secondary servers. None of those has any relationship to printing support.

  3. Question 3

    Buffer overflows are one of the major errors used for exploitation on the Internet today. A buffer overflow occurs when a particular operation/function writes more data into a variable than the variable was designed to hold. Which of the following are the two popular types of buffer overflows? Each correct answer represents a complete solution. (Choose two.)
    1. A. Dynamic buffer overflows
    2. B. Stack based buffer overflow
    3. C. Heap based buffer overflow
    4. D. Static buffer overflows
    Explanation

    The correct answers are: B. Stack based buffer overflow, C. Heap based buffer overflow.

    The two widely recognised categories of buffer overflow are distinguished by the memory region that is overrun. A stack based overflow overruns a buffer held in a function's stack frame, and it is the more straightforward to exploit because the saved return address and frame pointer sit close to local variables, so overflowing far enough lets an attacker choose where execution resumes when the function returns. A heap based overflow overruns memory obtained from the dynamic allocator, where there is no return address nearby, so exploitation instead corrupts allocator bookkeeping or object data such as function pointers in order to gain control. Dynamic and static buffer overflow are not established categories in this taxonomy. Buffers can of course be allocated statically or dynamically, but that describes where storage comes from rather than naming a recognised class of overflow, and neither term appears in the standard treatment of the subject.

  4. Question 4

    Which of the following statements about buffer overflow is true?
    1. A. It manages security credentials and public keys for message encryption.
    2. B. It is a collection of files used by Microsoft for software updates released between major service pack releases.
    3. C. It is a condition in which an application receives more data than it is configured to accept.
    4. D. It is a false warning about a virus.
    Explanation

    The correct answer is: C. It is a condition in which an application receives more data than it is configured to accept..

    A buffer overflow is a condition in which an application receives more data than it is configured to accept, so that the surplus is written past the end of the allocated region and into adjacent memory. Depending on what happens to occupy that neighbouring space, the consequences range from corrupted variables and a crash through to fully controlled redirection of execution when a saved return address is overwritten. The other options describe unrelated concepts. Managing security credentials and public keys for message encryption is the function of a public key infrastructure or a key management system. A collection of files issued by a vendor for updates between major service packs describes a cumulative update or hotfix rollup. A false warning about a virus is a hoax, which spreads through people forwarding it rather than through any technical defect. Only one option describes a memory-handling error, and that is what a buffer overflow is.

  5. Question 5

    Adam works as a Senior Programmer for Umbrella Inc. A project has been assigned to him to write a short program to gather user input for a Web application. He wants to keep his program neat and simple. His chooses to use printf(str) where he should have ideally used printf("%s", str). What attack will his program expose the Web application to?
    1. A. Format string attack
    2. B. Cross Site Scripting attack
    3. C. SQL injection attack
    4. D. Sequence++ attack
    Explanation

    The correct answer is: A. Format string attack.

    Passing a variable directly as the first argument to printf creates a format string vulnerability. The function treats that first argument as a template and consumes further arguments according to the conversion specifiers it finds, so when the template is attacker-controlled text the attacker chooses how many arguments are read and how they are interpreted. Specifiers that print pointers or strings can be used to read memory the program never intended to expose, and the specifier that writes the number of characters output so far can be used to write to a chosen address. Supplying a constant template and passing the untrusted text as a separate string argument removes the problem entirely, because the attacker no longer controls the template. The other options require conditions this code does not create: cross-site scripting needs output rendered by a browser, SQL injection needs a database query built from untrusted input, and the remaining option does not name a real attack.

Other GIAC Certified Incident Handler (GCIH) domains

Practice all 20 Exploitation and Privilege Escalation questions · Browse GIAC Certified Incident Handler (GCIH)