Browse all practice questions for the GIAC Security Essentials Certification (GSEC) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GIAC GSEC Practice Test - Prep & Study Guide for GIAC Security Essentials Certification course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What type of fire occurs when ordinary combustibles, such as paper or wood, catch fire?
  • What is a common use case for virtualizing servers?
  • If you wanted to set up a quick wireless network between several devices for a LAN party, what might you do?
  • What might be a sign that malware is present on a system?
  • Your firewall has a rule blocking inbound ICMP messages unless they are responses to a request originated from inside the network. Which attack is most likely being protected against?
  • How do viruses historically copy themselves from one system to another?
  • Which version of Windows 7 will NOT support connecting to Active Directory on your network?
  • What concept ensures that only the necessary privileges are granted to users?
  • If your vulnerability scan shows your Web server is vulnerable, but you are running version 2.6 of that software, what might be the reason?
  • Which of the following is not a benefit of VoIP?
  • In the network 192.168.5.0/23, what would be the broadcast address?
  • Which of the following protocols is used for secure communication over the internet?
  • What key combination generates a SIGINT signal in a terminal?
  • What is the main function of a firewall?
  • Intrusion prevention systems provide an advantage over IDSs and anti-virus programs for what type of attack?
  • Which of the following is a private address (RFC1918)?
  • Which of the following can be used to authenticate someone?
  • What is the primary function of a firewall?
  • If you wanted to generate keys in a secure fashion to exchange encrypted information, which process would you use?
  • What type of backup retains all data regardless of previous backups?
  • What is the primary function of a rootkit?
  • Which of the following is not a commonly used authentication factor?
  • What type of attack is typically characterized by overwhelming a system with traffic to disrupt services?
  • If vulnerability scans are routinely run but no one is reviewing the reports, what can be said about those scans?
  • In which scenario is ARP spoofing most likely occurring?
  • What does the command 'umask' control in a Linux system?
  • Which of the following does 802.11i NOT address?
  • What security control would a border router typically implement?
  • Which technology allows you to block network access based on the application being used to initiate the request?
  • What type of lock would be appropriate for securing a facility during unoccupied hours?
  • Why is Halon no longer manufactured?
  • A substitution steganography uses this part of a carrier file.
  • If you observe many ARP responses without matching ARP requests, what are you likely witnessing?
  • If your IDS alerts you about a packet with the same source and destination, what could this indicate?
  • What are two primary responsibilities of the hypervisor?
  • Which VMWare product is available for free to run virtual machines?
  • If you see the IP address fe80::0050:8790:4554:2300/16, what does the :: indicate?
  • Which of the following tactics might allow a perpetrator to gain a lot of information from a device?
  • What type of lock is considered more secure than standard locks for a facility?
  • What is a translation lookaside buffer used for?
  • What is the biggest problem with Bluetooth encryption?
  • What are Duqu and Stuxnet examples of?
  • To improve system security, which should be considered when installing applications?
  • Microsoft Windows file security permissions are an example of what?
  • What are significant challenges for intrusion detection systems?
  • What is the order of messages in a three-way handshake?
  • Which of the following is true regarding cron jobs in the syslog configuration?
  • Which term describes software that is designed to exploit vulnerabilities in computers or networks?
  • What can you say about the following packet capture: 14:18:25.906002 apollo.it.luc.edu.1000 > x-terminal.shell: S...?
  • What is the benefit of using snapshots in virtualization?
  • Which security principle emphasizes the need to limit user access rights to the bare minimum?
  • Which of the following is NOT typically considered a functionality of an intrusion detection system?
  • What effect does the iptables rule 'iptables -A INPUT -j DROP' have on network traffic?
  • What is a benefit of multifactor authentication?
  • Which feature of virtualization allows multiple operating systems to run on a single hardware platform?
  • Many wireless technologies make use of one simple technology to prevent eavesdropping on the signal. What is it?
  • Which utility would you use to monitor CPU usage of individual processes updated every three seconds?
  • Adding an additional alphanumeric character to the required length of a password will multiply the potential passwords by how many?
  • What technology does Microsoft Windows Update utilize to check for updates on a system?
  • Skype uses what type of communication to connect its users?
  • In IPv6, what is the purpose of the link-local address?
  • PGP uses what sort of system to verify the identity of the certificate holder?
  • What should your first action be before conducting an unscheduled vulnerability scan?
  • What security solution would you implement to prevent employees from browsing Facebook during work hours?
  • What type of attack does a firewall typically protect against?
  • What is the primary use of a spike strip in security?
  • What is a common characteristic of adware?
  • What can you accomplish by hiding your SSID?
  • Which of the following is NOT an example of where an adversary can gather useful information?
  • Network devices and dialup users may be authenticated using which of the following protocols?
  • What type of engineering is utilized by malware?
  • What is a common way in which ransomware operates?
  • In virtualization, what mechanism allows multiple VMs to share the same physical resources efficiently?
  • Which action is likely to help prevent infections from viruses?
  • Which strategy is recommended when using a quantitative risk assessment approach?
  • Which of the following VMWare files can be edited by hand in case of problems?
  • Which of the following is a reason why all vulnerabilities should not be addressed at once?
  • What is the primary goal of an incident response plan?
  • In what format are Windows Firewall logs stored?
  • Putting up signs serves as what type of control measure?
  • When creating a vulnerability scanning schedule for a large network, what is an effective strategy?
  • Which of these is a common method to enhance physical security in sensitive areas?
  • Which type of frame in WiFi announces SSID to the network?
  • Your intrusion detection system has alerted you that you are getting a SIP attack. What would you consider this attack to be, based solely on the information you have?
  • Which command would you use in a batch file to make changes to the Windows registry?
  • What is the primary difference between a virus and a worm?
  • Users are encouraged to use a pin of how many characters in order to better protect their Bluetooth communications?
  • What does a voice VLAN not offer you?
  • What is the primary benefit of using WPA over WEP?
  • Embedded wires in glass are designed to achieve which of the following?
  • If you observe unusual network traffic originating from your computer to foreign IPs, what could this suggest?
  • What is the most important criterion when deploying an intrusion prevention system on your network?
  • If your web browser generates a certificate error, which of the following is mostly likely to be the case?
  • What is the best way to protect data at rest?
  • Which of the following is an example of a passive security measure?
  • What type of attack is indicated by identical source and destination addresses in a packet?
  • What is a key advantage of a boot sector virus?
  • Which method can improve the security of a WiFi network?
  • What class is the address 170.19.82.45?
  • If the SLE for a system is $5,000 and the ARO is 2, what is the ALE?
  • A very primitive but popular type of encryption cipher is called what?
  • Without virtual memory, what were programmers typically required to use?
  • Which type of authentication does SIP use?
  • Vulnerability scanners do NOT do which of the following?
  • What does Java use to achieve architecture independence?
  • What is a good example of a network using a mesh topology?
  • Why might a UDP scan take longer to complete than other types of scans?
  • In order to validate a certificate presented to you, what would you need?
  • When creating a backup plan, which scheme would best balance recovery speed and storage space?
  • What type of security framework does WPA2 utilize?
  • Which of the following best defines a Denial of Service (DoS) attack?
  • What type of control is demonstrated by the use of a mantrap at the entrance of a facility?
  • What does PAM do to protect password security?
  • Which security model involves users having special privileges on a system?
  • What is the main purpose of using a hashing algorithm in password storage?
  • What tool would you use to enable auditing on systems in your network?
  • What does a vulnerability scan that identifies a firewall indicate?
  • Which decade saw the creation of the first virtual machines?
  • When is it most appropriate to conduct vulnerability scans?
  • Which protocol has historically been used by botnets for communication with handlers?
  • What does Microsoft recommend for assigning permissions to a set of users?
  • What is the principle of least privilege implemented in?
  • Which of the following best describes spyware?
  • If a file has permissions set to 744, what access rights do the user, group, and world get?
  • Which method is ineffective in breaking the security of a physical barrier?
  • What can be a major downside of using compression in an intrusion detection system?
  • What component does water primarily remove to extinguish a fire?
  • What is the primary function of an intrusion detection system?
  • Your bank is implementing a token-based solution for authentication. What type of authentication will they be using?
  • When implementing a star topology on your local network, what type of cabling are you most likely to use?
  • Which of these would be considered the most important part of cryptography?
  • The SUBSCRIBE message can be used for what purpose?
  • Which form of attack is specifically designed to exploit weaknesses in Bluetooth?
  • Which security measure is designed to protect a network by blocking unauthorized access while permitting outward communication?
  • In response to SQL injection errors detected in a commercial web application, which action would NOT be a part of remediation?
  • How many bits are in the NETWORK portion of the following address block: Address: 10.1.0.0, Subnet: 255.255.255.224?
  • Which command would you use to view the current running processes?
  • What does an organization need to ensure both complete operations recovery and continued operations?
  • Authentication is the process of doing what?
  • Which of the following is NOT a reason for packing a program?
  • SQL Injection attacks are targeted at what?
  • What functionality does TripWire provide in terms of security?
  • How would you define the host operating system?
  • To conduct static analysis on a piece of malware, what is a possible action?
  • After an evacuation, what is the best method to manage an airborne toxin?
  • What type of malware is indicated by the presence of new files in the temp directory that record user inputs?
  • Which file contains mappings between ports and the names of applications associated with them?
  • What is the subnet mask for the address block 10.1.0.0 with a /24 prefix?
  • How are security policies best described?
  • In the context of cybersecurity, what does the term "threat landscape" refer to?
  • The frequent appearance of popup ads while browsing the web is an indication of what type of malware?
  • What is one outcome when an application has not addressed known vulnerabilities?
  • If you want to perform basic filtering on your network interface without a firewall, what should you establish?
  • When advising on protecting a session ID in a web application, what is a recommended practice?
  • What is the purpose of a bollard?
  • What do intrusion detection systems NOT need in order to operate effectively?
  • A session border controller can help with which of the following security situations?
  • Which utility makes use of ICMP to function?
  • What's the difference between virtualization and emulation?
  • Which type of routing protocol uses the same algorithm as a car navigation system?
  • Which of these is a significant advantage to deploying an IDS?
  • In the address ab00:fc87:234a:0090:5120:ffab:bc8a:0098/23, what does the /23 indicate?
  • What technology is often used to enhance security in virtual environments?
  • Kerberos tickets allow users to do what?
  • According to the syslog configuration, where are login messages stored?
  • Which of the following practices is crucial for maintaining data integrity during data storage?
  • Which statement best describes an access control list used by border routers?
  • To determine whether a project makes financial sense, you would perform which of these?
  • Which command is used to set file permissions in Linux?
  • Where would you find statistics on the inet process with process ID 1 in your filesystem?
  • What does the SSID stand for in a wireless network context?
  • How should you prioritize the list of vulnerabilities from a Nexpose scan?
  • With the following IP header, what is the destination IP address: 45 00 03 3D 1E EB 40 00 40 06 5D E8 C0 A8 01 16 AD C2 4B 67?
  • RSA SecurID tokens provide what?
  • What does the SID S-1-15-32-545 represent?
  • Which of the following is not a component of a SIP message?
  • What is the purpose of the 'htop' utility?
  • What was SIP developed for?
  • Which of the following components does H.323 not specify in the networks?
  • If recyclables ignite due to high temperatures, what class of fire would this represent?
  • An effective risk management strategy may include which of the following?
  • What can John the Ripper be used for?
  • Which component is critical for maintaining user access in a domain environment?
  • What does NAT stand for in networking?
  • Which of these is NOT a reason for virtualizing?
  • The challenge of trying to find a collision in a hashing algorithm is called what?
  • Public key algorithms are also called what?
  • To which aspect of web applications should developers pay special attention to prevent session hijacking?
  • Backups and replication are two strategies primarily used for what purpose?
  • How can you enhance a group’s security permissions in Active Directory?
  • For which of the following scenarios would a deterrent control be most appropriate?
  • H.245 is used for what aspects of an H.323 session?
  • How could you enforce your policy that all Bluetooth devices disable discoverable mode?
  • How many phases does the Internet Key Exchange (IKE) have?
  • What can you infer if all results of a port scan show filtered ports?
  • What is a common use of Group Policy in a Windows environment?
  • Your boss wants to fix a critical vulnerability on the database server immediately. What should you do?
  • What might cause a tracert command to fail?
  • Which of the following will help protect a Web application infrastructure from Web attacks like SQL Injection?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy