Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free GIAC G2700 Practice Exam with Questions & Answers | Set: 9

Questions 81

Which of the following is a list of specific actions being taken to deal with specific risks associated with the threats?

Options:
A.

Risk mitigation

B.

Risk acceptance

C.

Risk avoidance

D.

Risk transference

GIAC G2700 Premium Access
Questions 82

Which of the following statements are true about Regulation of Investigatory Powers Act 2000?

Each correct answer represents a complete solution. Choose all that apply.

Options:
A.

It enables certain public bodies to demand ISPs fit equipment to facilitate surveillance.

B.

It enables mass surveillance of communications in transit.

C.

It enables certain private bodies to demand that someone hand over keys to protected information.

D.

It allows certain public bodies to monitor people's Internet activities.

Questions 83

You work as a Security Administrator for uCertify Inc. You are working on the disaster recovery plan (DRP) for IT related infrastructure recovery / continuity. Which of the following should you include in your plan?

Each correct answer represents a complete solution. Choose all that apply.

Options:
A.

Resumption of hardware

B.

Resumption of data

C.

Resumption of sales

D.

Resumption of applications

Questions 84

John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the company. To do so, he takes an image file and simply uses a tool image hide and embeds the secret file within an image file of the famous actress, Jennifer Lopez, and sends it to his Yahoo mail id. Since he is using the image file to send the data, the mail server of his company is unable to filter this mail. Which of the following techniques is he performing to accomplish his task?

Options:
A.

Steganography

B.

Email spoofing

C.

Web ripping

D.

Social engineering

Questions 85

A helpdesk technician received a phone call from an administrator at a remote branch office. The administrator claimed to have forgotten the password for the root account on UNIX servers and asked for it. Although the technician didn't know any administrator at the branch office, the guy sounded really friendly and since he knew the root password himself, he supplied the caller with the password.

What type of attack has just occurred?

Options:
A.

Brute Force attack

B.

War dialing attack

C.

Social Engineering attack

D.

Replay attack

Questions 86

Which of the following tools can be used for steganography?

Each correct answer represents a complete solution. Choose all that apply.

Options:
A.

Snow.exe

B.

Stegbreak

C.

Anti-x

D.

Image hide

Questions 87

Which of the following is a list of specific actions being taken to deal with specific risks associated with the threats?

Options:
A.

Risk acceptance

B.

Risk transference

C.

Risk avoidance

D.

Risk mitigation

Questions 88

You work as an Information Security Manager for uCertify Inc. You are working on a software asset management plan to provide backup for Active Directory. Which of the following data is required to be backed up for this purpose?

Options:
A.

System state data

B.

Users manual

C.

DNS record

D.

Cache memory

Questions 89

Mark is the project manager of the NHQ project in StarTech Inc. The project has an asset valued at $195,000 and is subjected to an exposure factor of 35 percent. What will be the Single Loss Expectancy of the project?

Options:
A.

$67,250

B.

$92,600

C.

$72,650

D.

$68,250

Questions 90

As an attacker, you are sending very small sized packets with durations of 15 minutes per packet to the IIS Web server. Since an IIS session remains alive for a long time, the IDS may be tricked into accepting them as regular packet transformations. Which of the following types of attacking methods are you using?

Options:
A.

Session splicing

B.

Nonblind spoofing

C.

Session hijacking

D.

Security Logging

GIAC Related Exams

GIAC Free Exams

GIAC Free Exams
Prepare for GIAC certification with free access to reliable study resources and practice tests at Examstrack.