Network Attacks and Denial of Service for GIAC Certified Incident Handler (GCIH)

This page covers the Network Attacks and Denial of Service domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 86 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Which of the following types of attacks is only intended to make a computer resource unavailable to its users?
    1. A. Denial of Service attack
    2. B. Replay attack
    3. C. Teardrop attack
    4. D. Land attack
    Explanation

    The correct answer is: A. Denial of Service attack.

    A denial of service attack is the one whose only intent is to make a computer resource unavailable to its users. That single purpose is the defining feature: the attacker gains no access, reads no data and alters nothing, and success is measured purely in the service being unusable. The other options either pursue a different goal or name a specific technique within this family. A replay attack presents captured data again in order to gain access, so its objective is unauthorised use rather than disruption. Teardrop and land are both genuine denial of service techniques, teardrop sending overlapping fragments that a vulnerable stack mishandles on reassembly and land sending a packet whose source and destination are identical to confuse a stack, but each names one particular method. The question asks for the category defined by intent, which is why the general term is the answer rather than either specific attack.

  2. Question 2

    In which of the following DoS attacks does an attacker send an ICMP packet larger than 65,536 bytes to the target system?
    1. A. Ping of death
    2. B. Jolt
    3. C. Fraggle
    4. D. Teardrop
    Explanation

    The correct answer is: A. Ping of death.

    The ping of death is the attack that sends an ICMP packet larger than 65,536 bytes to the target. Because that exceeds the maximum size the protocol allows, the packet has to be delivered as fragments, and the damage occurs when a stack that does not validate the total reassembled length copies the result into a buffer sized for a legal packet and overflows it, crashing the system. The other options are different attacks. Jolt is related in that it also relies on oversized fragmented traffic, but the name specifically associated with the oversized echo request is the one given. Fraggle sends user datagram protocol echo traffic to a broadcast address with a forged source, which is an amplification flood rather than a malformed packet attack. Teardrop also abuses fragmentation but does so with overlapping offsets rather than excessive total size, so the failure is in reassembly arithmetic rather than in length.

  3. Question 3

    Adam has installed and configured his wireless network. He has enabled numerous security features such as changing the default SSID, enabling WPA encryption, and enabling MAC filtering on his wireless router. Adam notices that when he uses his wireless connection, the speed is sometimes 16 Mbps and sometimes it is only 8 Mbps or less. Adam connects to the management utility wireless router and finds out that a machine with an unfamiliar name is connected through his wireless connection. Paul checks the router's logs and notices that the unfamiliar machine has the same MAC address as his laptop. Which of the following attacks has been occurred on the wireless network of Adam?
    1. A. NAT spoofing
    2. B. DNS cache poisoning
    3. C. MAC spoofing
    4. D. ARP spoofing
    Explanation

    The correct answer is: C. MAC spoofing.

    The decisive detail is that the unfamiliar machine shows the same hardware address as the owner's own laptop, which means the intruder has changed the address of their adapter to match one the access point already permits. That is hardware address spoofing, and it explains why the filtering configured on the router failed to stop it: addresses travel unencrypted in every frame, so an attacker within range simply observes a permitted address and adopts it, which is why address filtering should be understood as a deterrent rather than a real control. The other options do not fit. Address resolution spoofing sends forged replies to redirect traffic between hosts, which is not what a duplicate hardware address in a router's log indicates. Name resolution cache poisoning inserts false records into a resolver. Address translation spoofing is not an established attack name.

  4. Question 4

    Which of the following statements are true about tcp wrappers? Each correct answer represents a complete solution. (Choose all that apply.)
    1. A. tcp wrapper provides access control, host address spoofing, client username lookups, etc.
    2. B. When a user uses a TCP wrapper, the inetd daemon runs the wrapper program tcpd instead of running the server program directly.
    3. C. tcp wrapper allows host or subnetwork IP addresses, names and/or ident query replies, to be used as tokens to filter for access control purposes.
    4. D. tcp wrapper protects a Linux server from IP address spoofing.
    Explanation

    The correct answers are: A. tcp wrapper provides access control, host address spoofing, client username lookups, etc., B. When a user uses a TCP wrapper, the inetd daemon runs the wrapper program tcpd instead of running the server program directly., C. tcp wrapper allows host or subnetwork IP addresses, names and/or ident query replies, to be used as tokens to filter for access control purposes..

    Three statements are accurate. A wrapper provides access control together with related facilities such as logging, host name checking and client username lookups. When it is in use the service dispatcher runs the wrapper program rather than the requested server directly, so the wrapper makes its decision first and only then hands the connection over. And it allows addresses, network ranges, names and identification query replies to be used as tokens in its access control rules. The false statement is the one claiming it protects a server from address spoofing. It cannot, and the reason is fundamental: a wrapper decides whether to permit a connection by consulting the source address and name the packet presents, so if that information is forged the wrapper is being deceived by the very data it relies on. Access control based on network identity is only ever as trustworthy as the identity itself.

  5. Question 5

    Which of the following statements about Denial-of-Service (DoS) attack are true? Each correct answer represents a complete solution. (Choose three.)
    1. A. It disrupts services to a specific computer.
    2. B. It changes the configuration of the TCP/IP protocol.
    3. C. It saturates network resources.
    4. D. It disrupts connections between two computers, preventing communications between services.
    Explanation

    The correct answers are: A. It disrupts services to a specific computer., C. It saturates network resources., D. It disrupts connections between two computers, preventing communications between services..

    Three statements are true. A denial of service disrupts services to a specific computer, which is the usual objective. It saturates network resources, which is the most common mechanism, since bandwidth and connection state are finite. And it disrupts connections between two computers, preventing communication between services, which is the effect on traffic that was already in progress. Together these describe intent, mechanism and effect. The false statement is the one claiming the attack changes the configuration of the protocol stack. Nothing about a denial of service alters configuration: the attacker sends traffic that the stack processes exactly as designed until a resource runs out, and no setting is modified on the victim. That distinction matters in practice, because a system recovers as soon as the flood stops, whereas an attack that had genuinely changed configuration would require the change to be found and reversed.

Other GIAC Certified Incident Handler (GCIH) domains

Practice all 86 Network Attacks and Denial of Service questions · Browse GIAC Certified Incident Handler (GCIH)