Reconnaissance, Scanning, and Mapping for GIAC Certified Incident Handler (GCIH)

This page covers the Reconnaissance, Scanning, and Mapping domain of the GIAC Certified Incident Handler (GCIH) certification. Master Cybersecurity offers 86 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Which of the following is a technique of using a modem to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for computers, Bulletin board systems, and fax machines?
    1. A. Demon dialing
    2. B. Warkitting
    3. C. War driving
    4. D. Wardialing
    Explanation

    The correct answer is: D. Wardialing.

    Wardialing is the technique of using a modem to work through a list of telephone numbers automatically, typically every number in an exchange, looking for computers, bulletin board systems and fax machines that answer. Its value to an attacker is that a modem answering a call may provide a route into a network that bypasses the firewall entirely, and such lines are frequently installed for out-of-hours maintenance and then forgotten by everyone except the person who installed them. The other options describe different things. Demon dialing repeatedly calls one number rather than sweeping many, usually to attack a login, and confusing the two is the classic error. War driving is the wireless equivalent, moving through an area to discover networks by radio rather than by telephone. Warkitting refers to compromising a home router to alter its configuration and is unrelated to dialling.

  2. Question 2

    Network mapping provides a security testing team with a blueprint of the organization. Which of the following steps is NOT a part of manual network mapping?
    1. A. Gathering private and public IP addresses
    2. B. Collecting employees information
    3. C. Banner grabbing
    4. D. Performing Neotracerouting
    Explanation

    The correct answer is: D. Performing Neotracerouting.

    Manual network mapping means building a picture of a target using research and hand-driven queries, so the step that does not belong is the one performed by running an automated route tracing product. Gathering private and public addresses, collecting information about employees and grabbing service banners are all activities an analyst carries out directly, reading records, connecting to services and reasoning about what is found. Running a graphical trace utility is automation, and it is the tool that produces the map rather than the manual method of producing one. The distinction matters more than it first appears, because manual techniques are quiet and often leave nothing in the target's logs, whereas an automated trace generates traffic to the target and to every hop in between. An analyst who wants to stay unobserved does the manual work first and reaches for automation only once noise is acceptable.

  3. Question 3

    Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?
    1. A. Whishker
    2. B. Nessus
    3. C. SARA
    4. D. Nmap
    Explanation

    The correct answer is: B. Nessus.

    Nessus is the vulnerability scanner that can invoke an external password cracking tool to attempt a dictionary attack. Its plugin architecture allows checks to call helper programs, so when a scan finds an authenticating service the scanner can hand off to the specialist tool and report any account it recovers as a finding alongside the rest. That integration is why a scan may return weak credentials as well as missing patches. The other options do not work this way. Nmap discovers hosts, ports, services and platforms, and while it can run scripts, it is a mapping tool rather than a vulnerability database driving credential attacks. SARA is an auditing tool in the same family but is not the product associated with this integration. Whisker, whose name appears misspelled in the options, is a web server scanner concerned with scripts and server-side flaws rather than with authentication.

  4. Question 4

    Which of the following commands is used to access Windows resources from Linux workstation?
    1. A. mutt
    2. B. scp
    3. C. rsync
    4. D. smbclient
    Explanation

    The correct answer is: D. smbclient.

    smbclient is the command for reaching Windows resources from a Linux workstation. It speaks the Windows file sharing protocol and presents an interface resembling a file transfer client, so shares on a Windows host can be listed and files retrieved or sent without mounting anything, which also makes it useful for enumerating what a host publishes. The other commands serve different purposes. scp copies files between hosts over an encrypted channel and requires that protocol at the far end, which a Windows host does not offer by default. rsync synchronises directory trees efficiently and likewise expects its own service or an encrypted shell to be available. mutt is a mail client and has nothing to do with file access at all. Choosing the right client for the protocol the remote host actually speaks is the practical point of the question.

  5. Question 5

    Adam, a malicious hacker, wants to perform a reliable scan against a remote target. He is not concerned about being stealth at this point. Which of the following type of scans would be most accurate and reliable?
    1. A. UDP sacn
    2. B. TCP Connect scan
    3. C. ACK scan
    4. D. Fin scan
    Explanation

    The correct answer is: B. TCP Connect scan.

    A full connection scan is the most accurate and reliable technique, which is why it is the right choice for an attacker who has decided stealth does not matter. Completing the handshake produces an unambiguous result, since a service that accepts a connection is definitively listening, and because it uses the ordinary connection facility rather than crafted packets it behaves consistently across every platform and requires no special privilege. The cost is visibility, as every connection is a candidate for logging. The other options trade accuracy for stealth or serve different purposes. A FIN scan depends on a stack following the specification and gives no useful result against Windows. An acknowledgement scan is designed to map filtering rules rather than to determine reliably whether a service is listening. A user datagram protocol scan is inherently less certain because an open port often returns nothing at all, so absence of response is ambiguous.

Other GIAC Certified Incident Handler (GCIH) domains

Practice all 86 Reconnaissance, Scanning, and Mapping questions · Browse GIAC Certified Incident Handler (GCIH)