GIAC Certified Enterprise Defender GCED Exam Questions

Page: 1 / 14
Total 88 questions
Question 1

You have been tasked with searching for Alternate Data Streams on the following collection of Windows partitions; 2GB FAT16, 6GB FAT32, and 4GB NTFS. How many total Gigabytes and partitions will you need to search?



Answer : C


Question 2

What should happen before acquiring a bit-for-bit copy of suspect media during incident response?



Answer : B


Question 3

Which tool uses a Snort rules file for input and by design triggers Snort alerts?



Answer : C


Question 4

A company estimates a loss of $2,374 per hour in sales if their website goes down. Their webserver hosting site's documented downtime was 7 hours each quarter over the last two years. Using the information, what can the analyst determine?



Answer : A

The annualized loss expectancy (ALE) is deduced by multiplying the single loss expectancy (SLE) by the annual rate of occurrence (ARO); in this example $2, 374 (7 4), respectively. This is a form of Quantitative risk analysis. Qualitative risk posture is deduced by measuring and contrasting the likelihood (probability of occurrence) with the level of impact and by definition does not address risk using monetary figures. Total cost of ownership (TCO) is the sum of all costs (technical, administrative, environmental, et al) that are involved for a specific system, service, etc. CVSS risk scoring is not based off of this type of loss data.


Question 5

When an IDS system looks for a pattern indicating a known worm, what type of detection method is it using?



Answer : A


Question 6

Michael, a software engineer, added a module to a banking customer's code. The new module deposits small amounts of money into his personal bank account. Michael has access to edit the code, but only code reviewers have the ability to commit modules to production. The code reviewers have a backlog of work, and are often willing to trust the software developers' testing and confidence in the code.

Which technique is Michael most likely to engage to implement the malicious code?



Answer : C


Question 7

An analyst will capture traffic from an air-gapped network that does not use DNS. The analyst is looking for unencrypted Syslog data being transmitted. Which of the following is most efficient for this purpose?



Answer : B

When using tcpdump, a --n switch will tell the tool to not resolve hostnames; as this network makes no use of DNS this is efficient. The --vv switch increases the tools output verbosity. The --s0 increases the snaplength to ''all'' rather than the default of 96 bytes. The --nnvvX would make sense here except that the port in the filter is 6514 which is the default port for encrypted Syslog transmissions.


Page:    1 / 14   
Total 88 questions