GCED Exam Questions
96 real GCED exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
At the start of an investigation on a Windows system, the lead handler executes the following commands after inserting a USB drive. What is the purpose of this command? C:\ >dir /...
- Question #3
Why would the pass action be used in a Snort configuration file?
- Question #4
On which layer of the OSI Reference Model does the FWSnort utility function?
- Question #5
What feature of Wireshark allows the analysis of one HTTP conversation?
- Question #6
From a security perspective, how should the Root Bridge be determined in a Spanning Tree Protocol (STP) environment?
- Question #7
Which tasks would a First Responder perform during the Identification phase of Incident Response?
- Question #8
What should happen before acquiring a bit-for-bit copy of suspect media during incident response?
- Question #9
How does the Cisco IOS IP Source Guard feature help prevent spoofing attacks?
- Question #10
Which control would BEST help detect a potential insider threat?
- Question #11
How would an attacker use the following configuration settings?
- Question #12
What is the most common read-only SNMP community string usually called?
- Question #13
What would a penetration tester expect to access after the following metasploit payload is delivered successfully? Set PAYLOAD windows / shell / reverse _ tcp
- Question #14
Requiring background checks for employees who access protected data is an example of which type of data loss control?
- Question #15
Which of the following is an operational security control that is used as a prevention mechanism?
- Question #16
Why would a Cisco network device with the latest updates and patches have the service config setting enabled, making the device vulnerable to the TFTP Server Attack?
- Question #17
In order to determine if network traffic adheres to expected usage and complies with technical standards, an organization would use a device that provides which functionality?
- Question #18
Which of the following tools is the most capable for removing the unwanted add-on in the screenshot below?
- Question #19
An analyst will capture traffic from an air-gapped network that does not use DNS. The analyst is looking for unencrypted Syslog data being transmitted. Which of the following is mo...
- Question #20
Throughout the week following a new IPS deployment, nearly every user on the protected subnet submits helpdesk tickets regarding network performance and not being able to access se...
- Question #21
Which of the following is best defined as "anything that has the potential to target known or existing vulnerabilities in a system?"
- Question #22
An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization's security policy. The...
- Question #23
Which action would be the responsibility of the First Responder once arriving at the scene of a suspected incident as part of a Computer Security Incident Response Plan (CSIRP)?
- Question #24
A company classifies data using document footers, labeling each file with security labels "Public", "Pattern", or "Company Proprietary". A new policy forbids sending "Company Propr...
- Question #25
Although the packet listed below contained malware, it freely passed through a layer 3 switch. Why didn't the switch detect the malware in this packet?
- Question #26
In an 802.1x deployment, which of the following would typically be considered a Supplicant?
- Question #27
You have been tasked with searching for Alternate Data Streams on the following collection of Windows partitions; 2GB FAT16, 6GB FAT32, and 4GB NTFS. How many total Gigabytes and p...
- Question #28
What piece of information would be recorded by the first responder as part of the initial System Description?
- Question #29
Which type of attack could be used to obtain IOS router configuration files without a valid user password?
- Question #30
Following a Digital Forensics investigation, which of the following should be included in the final forensics report?
- Question #31
The matrix in the screen shot below would be created during which process?
- Question #32
Which Windows CLI tool can identify the command-line options being passed to a program at startup?
- Question #33
An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed....
- Question #34
What does the following WMIC command accomplish? process where name='malicious.exe' delete
- Question #35
An analyst wants to see a grouping of images that may be contained in a pcap file. Which tool natively meets this need?
- Question #36
Which of the following is considered a preventative control in operational security?
- Question #37
Which command is the Best choice for creating a forensic backup of a Linux system?
- Question #38
Which of the following would be included in a router configuration standard?
- Question #39
Requiring criminal and financial background checks for new employees is an example of what type of security control?
- Question #40
You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexp...
- Question #41
Which of the following applies to newer versions of IOS that decrease their attack surface?
- Question #42
The security team wants to detect connections that can compromise credentials by sending them in plaintext across the wire. Which of the following rules should they enable on their...
- Question #43
Which Windows tool would use the following command to view a process: process where name='suspect_malware.exe'list statistics
- Question #44
Which of the following is an outcome of the initial triage during incident response?
- Question #45
Which of the following is the best way to establish and verify the integrity of a file before copying it during an investigation?
- Question #46
What would the output of the following command help an incident handler determine? cscript manage-bde . wsf -status
- Question #47
What information would the Wireshark filter in the screenshot list within the display window?
- Question #48
What are Browser Helper Objects (BHO)s used for?
- Question #49
What is needed to be able to use taskkill to end a process on remote system?
- Question #50
A compromised router is reconfigured by an attacker to redirect SMTP email traffic to the attacker's server before sending packets on to their intended destinations. Which IP heade...
- Question #51
Which tool keeps a backup of all deleted items, so that they can be restored later if need be?