New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

GCCC GIAC Critical Controls Certification (GCCC) Questions and Answers

Questions 4

If an attacker wanted to dump hashes or run wmic commands on a target machine, which of the following tools would he use?

Options:

A.

Mimikatz

B.

OpenVAS

C.

Metasploit

Buy Now
Questions 5

Which of the following statements is appropriate in an incident response report?

Options:

A.

There had been a storm on September 27th that may have caused a power surge

B.

The registry entry was modified on September 29th at 22:37

C.

The attacker may have been able to access the systems due to missing KB2965111

D.

The backup process may have failed at 2345 due to lack of available bandwidth

Buy Now
Questions 6

Kenya is a system administrator for SANS. Per the recommendations of the CIS Controls she has a dedicated host (kenya- adminbox / 10.10.10.10) for any administrative tasks. She logs into the dedicated host with her domain admin credentials. Which of the following connections should not exist from kenya-adminbox?

Options:

A.

10.10.245.3389

B.

Mail.jane.org.25

C.

Firewall_charon.jane.org.22

D.

10.10.10.33.443

Buy Now
Questions 7

Given the audit finding below, which CIS Control was being measured?

Options:

A.

Controlled Access Based on the Need to Know

B.

Controlled Use of Administrative Privilege

C.

Limitation and Control of Network Ports, Protocols and Services

D.

Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers

E.

Inventory and Control of Hardware Assets

Buy Now
Questions 8

Which of the following is a responsibility of a change management board?

Options:

A.

Reviewing log files for unapproved changes

B.

Approving system baseline configurations.

C.

Providing recommendations for the changes

D.

Reviewing configuration of the documents

Buy Now
Questions 9

What tool creates visual network topology output and results that can be analyzed by Ndiff to determine if a service or network asset has changed?

Options:

A.

Ngrep

B.

CIS-CAT

C.

Netscreen

D.

Zenmap

Buy Now
Questions 10

Which of the following actions will assist an organization specifically with implementing web application software security?

Options:

A.

Making sure that all hosts are patched during regularly scheduled maintenance

B.

Providing end-user security training to both internal staff and vendors

C.

Establishing network activity baselines among public-facing servers

D.

Having a plan to scan vulnerabilities of an application prior to deployment

Buy Now
Questions 11

An administrator looking at a web application’s log file found login attempts by the same host over several seconds. Each user ID was attempted with three different passwords. The event took place over 5 seconds.

  • ROOT
  • TEST
  • ADMIN
  • SQL
  • USER
  • NAGIOSGUEST

What is the most likely source of this event?

Options:

A.

An IT administrator attempting to use outdated credentials to enter the site

B.

An attempted Denial of Service attack by locking out administrative accounts

C.

An automated tool that attempts to use a dictionary attack to infiltrate a website

D.

An attempt to use SQL Injection to gain information from a web-connected database

Buy Now
Questions 12

An organization is implementing an application software security control their custom-written code that provides web—based database access to sales partners. Which action will help mitigate the risk of the application being compromised?

Options:

A.

Providing the source code for their web application to existing sales partners

B.

Identifying high-risk assets that are on the same network as the web application server

C.

Creating signatures for their IDS to detect attacks specific to their web application

D.

Logging the connection requests to the web application server from outside hosts

Buy Now
Questions 13

Which projects enumerates or maps security issues to CVE?

Options:

A.

SCAP

B.

CIS Controls

C.

NIST

D.

ISO 2700

Buy Now
Exam Code: GCCC
Exam Name: GIAC Critical Controls Certification (GCCC)
Last Update: Dec 22, 2024
Questions: 93

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99