Malware, Persistence, and Covering Tracks for GIAC Certified Incident Handler (GCIH)
This page covers the Malware, Persistence, and Covering Tracks domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 105 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.
Sample Practice Questions
Question 1
Adam, a novice computer user, works primarily from home as a medical professional. He just bought a brand new Dual Core Pentium computer with over 3 GB of RAM. After about two months of working on his new computer, he notices that it is not running nearly as fast as it used to. Adam uses antivirus software, anti- spyware software, and keeps the computer up-to-date with Microsoft patches. After another month of working on the computer, Adam finds that his computer is even more noticeably slow. He also notices a window or two pop-up on his screen, but they quickly disappear. He has seen these windows show up, even when he has not been on the Internet. Adam notices that his computer only has about 10 GB of free space available. Since his hard drive is a 200 GB hard drive, Adam thinks this is very odd. Which of the following is the mostly likely the cause of the problem?- A. Computer is infected with the stealth kernel level rootkit.
- B. Computer is infected with stealth virus.
- C. Computer is infected with the Stealth Trojan Virus.
- D. Computer is infected with the Self-Replication Worm.
Explanation
The correct answer is: A. Computer is infected with the stealth kernel level rootkit..
The combination of symptoms points to a stealth kernel level rootkit. The decisive detail is the disk space: a large amount is unaccounted for, and a rootkit operating in the kernel can intercept the calls through which the system reports file and volume information, so material it has stored is simply omitted from what the user is shown. The progressive slowing and the windows appearing briefly even when the machine is offline indicate code running on its own initiative, and the failure of current protective software to find anything is consistent with concealment at a privilege level at or above the scanner. The other options fit less well. A stealth virus conceals changes to files it infects but would not hide tens of gigabytes. The trojan and worm options describe delivery and propagation rather than the concealment that explains the missing space.
Question 2
Which of the following applications is an example of a data-sending Trojan?- A. SubSeven
- B. Senna Spy Generator
- C. Firekiller 2000
- D. eBlaster
Explanation
The correct answer is: D. eBlaster.
The product named in the correct option is the example of a data-sending trojan. Its defining behaviour is that it collects information on the host, including keystrokes, messages and visited sites, and then transmits that material out to the attacker by electronic mail, so the data flows outward on a schedule rather than the attacker connecting inward. That direction of flow is what places it in this category and also what makes it awkward to detect, since outbound mail is ordinary traffic. The other options belong to different categories. SubSeven is a remote access trojan, giving the attacker interactive control of the machine. Firekiller 2000 is a security software disabler, whose purpose is to shut down protective products so that other code can operate. Senna Spy Generator is a construction kit for producing trojans rather than a trojan with behaviour of its own.
Question 3
Which of the following statements are true about worms? Each correct answer represents a complete solution. (Choose all that apply.)- A. Worms cause harm to the network by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer.
- B. Worms can exist inside files such as Word or Excel documents.
- C. One feature of worms is keystroke logging.
- D. Worms replicate themselves from one system to another without using a host file.
Explanation
The correct answers are: A. Worms cause harm to the network by consuming bandwidth, whereas viruses almost always corrupt or modify files on a targeted computer., B. Worms can exist inside files such as Word or Excel documents., D. Worms replicate themselves from one system to another without using a host file..
Three statements hold. Worms harm a network largely by consuming bandwidth as they propagate, whereas viruses characteristically corrupt or modify files on the machine they infect, which is a fair summary of where each does its damage. Worms replicate from one system to another without needing a host file, which is the defining distinction from a virus. And worm code can be carried inside documents, since a document capable of executing script can serve as a container for self-propagating code. The false statement is the one attributing keystroke logging to worms as a feature. Logging keystrokes is the function of a keylogger, and while a worm may certainly carry one as part of its payload, that is a matter of what a particular specimen was written to deliver rather than a characteristic of worms as a category.
Question 4
Adam works as a Security Analyst for Umbrella Inc. Company has a Windows-based network. All computers run on Windows XP. Manager of the Sales department complains Adam about the unusual behavior of his computer. He told Adam that some pornographic contents are suddenly appeared on his computer overnight. Adam suspects that some malicious software or Trojans have been installed on the computer. He runs some diagnostics programs and Port scanners and found that the Port 12345, 12346, and 20034 are open. Adam also noticed some tampering with the Windows registry, which causes one application to run every time when Windows start. Which of the following is the most likely reason behind this issue?- A. Cheops-ng is installed on the computer.
- B. Elsave is installed on the computer.
- C. NetBus is installed on the computer.
- D. NetStumbler is installed on the computer.
Explanation
The correct answer is: C. NetBus is installed on the computer..
Ports 12345, 12346 and 20034 together with a registry entry causing a program to run at every start-up identify the trojan named in the correct option. The first two ports are that family's long-standing defaults and the third belongs to its later version, so seeing all three is close to conclusive, and the registry modification is the persistence mechanism that keeps it running across restarts. The pornographic content appearing overnight is consistent with an attacker having interactive control of the desktop. The other options are not trojans at all, which is what makes them straightforward to eliminate. Cheops-ng is a network mapping and visualisation tool. Elsave is a utility for clearing Windows event logs, which an attacker might well use afterwards but which opens no ports. NetStumbler is a wireless network discovery tool.
Question 5
You have configured a virtualized Internet browser on your Windows XP professional computer. Using the virtualized Internet browser, you can protect your operating system from which of the following?- A. Brute force attack
- B. Mail bombing
- C. Distributed denial of service (DDOS) attack
- D. Malware installation from unknown Web sites
Explanation
The correct answer is: D. Malware installation from unknown Web sites.
Running the browser in a virtualised environment protects the operating system from malicious software installed by unknown web sites. The mechanism is containment rather than prevention: hostile code delivered through the browser executes inside the virtual environment, where its changes affect a disposable instance that can be discarded and rebuilt rather than the underlying system. That is why the technique is used for deliberately visiting untrustworthy sites. The other options are unaffected. A brute force attack submits candidate credentials against a service and is not influenced by how the browser is hosted. Mail bombing floods a mailbox with messages, which concerns the mail service rather than the browser. A distributed denial of service exhausts bandwidth or resources from many hosts, and virtualisation neither reduces the traffic arriving nor prevents the machine being affected by a saturated network.
Other GIAC Certified Incident Handler (GCIH) domains
- Exploitation and Privilege Escalation (20 questions)
- Incident Response and Cyber Investigation (57 questions)
- Network Attacks and Denial of Service (86 questions)
- Password and Credential Attacks (21 questions)
- Reconnaissance, Scanning, and Mapping (86 questions)
- Web Application Attacks (29 questions)