GCED Exam Questions
96 real GCED exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Data Protection and Incident Response
At the start of an investigation on a Windows system, the lead handler executes the following commands after inserting a USB drive. What is the purpose of this command? C:\ >dir /...
Windows forensicscommand-line toolsincident responseevidence collection - Question #3Perimeter Security and Intrusion Detection
Why would the pass action be used in a Snort configuration file?
Snort rulesIDS configurationrule actionspacket filtering - Question #4Perimeter Security and Intrusion Detection
On which layer of the OSI Reference Model does the FWSnort utility function?
FWSnortOSI modeliptablesIDS tools - Question #5Enterprise Network Security and Network Services Security
What feature of Wireshark allows the analysis of one HTTP conversation?
WiresharkTCP stream analysispacket captureHTTP traffic - Question #6Enterprise Network Security and Network Services Security
From a security perspective, how should the Root Bridge be determined in a Spanning Tree Protocol (STP) environment?
Spanning Tree ProtocolSTP securityroot bridge selectionswitching - Question #7Data Protection and Incident Response
Which tasks would a First Responder perform during the Identification phase of Incident Response?
incident responseidentification phasefirst responderIR lifecycle - Question #8Data Protection and Incident Response
What should happen before acquiring a bit-for-bit copy of suspect media during incident response?
forensic imagingchain of custodyhash verificationevidence integrity - Question #9Enterprise Network Security and Network Services Security
How does the Cisco IOS IP Source Guard feature help prevent spoofing attacks?
IP Source GuardCisco IOSDHCP snoopinganti-spoofing - Question #10Defense-in-Depth and Security Architecture
Which control would BEST help detect a potential insider threat?
insider threatprivileged accessaccess controldetection controls - Question #11Enterprise Network Security and Network Services Security
How would an attacker use the following configuration settings?
MITM attackrouter configurationnetwork attacksrouting manipulation - Question #12Enterprise Network Security and Network Services Security
What is the most common read-only SNMP community string usually called?
SNMPcommunity stringdefault credentialsnetwork management - Question #13Host Security and Management
What would a penetration tester expect to access after the following metasploit payload is delivered successfully? Set PAYLOAD windows / shell / reverse _ tcp
Metasploitreverse shellpayload typespenetration testing - Question #14Data Protection and Incident Response
Requiring background checks for employees who access protected data is an example of which type of data loss control?
data loss preventionpersonnel securitybackground checksprevention controls - Question #15Defense-in-Depth and Security Architecture
Which of the following is an operational security control that is used as a prevention mechanism?
operational securityasset labelingprevention controlssecurity control types - Question #16Enterprise Network Security and Network Services Security
Why would a Cisco network device with the latest updates and patches have the service config setting enabled, making the device vulnerable to the TFTP Server Attack?
Cisco IOSTFTP vulnerabilitydefault settingsnetwork device hardening - Question #17Perimeter Security and Intrusion Detection
In order to determine if network traffic adheres to expected usage and complies with technical standards, an organization would use a device that provides which functionality?
protocol anomaly detectionnetwork monitoringIDS/IPStraffic analysis - Question #18Host Security and Management
Which of the following tools is the most capable for removing the unwanted add-on in the screenshot below?
malware removalbrowser add-onTaskkillendpoint tools - Question #19Enterprise Network Security and Network Services Security
An analyst will capture traffic from an air-gapped network that does not use DNS. The analyst is looking for unencrypted Syslog data being transmitted. Which of the following is mo...
tcpdumpSyslogpacket capturenetwork traffic analysis - Question #20Perimeter Security and Intrusion Detection
Throughout the week following a new IPS deployment, nearly every user on the protected subnet submits helpdesk tickets regarding network performance and not being able to access se...
IPS deploymentinline TAPnetwork performanceIPS tuning - Question #21Defense-in-Depth and Security Architecture
Which of the following is best defined as "anything that has the potential to target known or existing vulnerabilities in a system?"
threat definitionsecurity terminologyattack vectorvulnerability concepts - Question #22Enterprise Network Security and Network Services Security
An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization's security policy. The...
firewall rulesauditingaccess controlsecurity policy - Question #23Data Protection and Incident Response
Which action would be the responsibility of the First Responder once arriving at the scene of a suspected incident as part of a Computer Security Incident Response Plan (CSIRP)?
incident responseCSIRPfirst responderIR roles - Question #24Data Protection and Incident Response
A company classifies data using document footers, labeling each file with security labels "Public", "Pattern", or "Company Proprietary". A new policy forbids sending "Company Propr...
DLPdata classificationSMTP monitoringemail security - Question #25Perimeter Security and Intrusion Detection
Although the packet listed below contained malware, it freely passed through a layer 3 switch. Why didn't the switch detect the malware in this packet?
deep packet inspectionlayer 3 switchingmalware detectionnetwork devices - Question #26Enterprise Network Security and Network Services Security
In an 802.1x deployment, which of the following would typically be considered a Supplicant?
802.1xnetwork access controlsupplicantRADIUS - Question #27Data Protection and Incident Response
You have been tasked with searching for Alternate Data Streams on the following collection of Windows partitions; 2GB FAT16, 6GB FAT32, and 4GB NTFS. How many total Gigabytes and p...
alternate data streamsNTFSfile system forensicsFAT32 - Question #28Data Protection and Incident Response
What piece of information would be recorded by the first responder as part of the initial System Description?
first respondersystem documentationincident responsechain of custody - Question #29Enterprise Network Security and Network Services Security
Which type of attack could be used to obtain IOS router configuration files without a valid user password?
router securityTFTPIOS configurationnetwork attack - Question #30Data Protection and Incident Response
Following a Digital Forensics investigation, which of the following should be included in the final forensics report?
forensics reportdigital forensicsincident documentationexecutive summary - Question #31Defense-in-Depth and Security Architecture
The matrix in the screen shot below would be created during which process?
risk assessmentrisk matrixrisk analysissecurity management - Question #32Host Security and Management
Which Windows CLI tool can identify the command-line options being passed to a program at startup?
WMICWindows CLIprocess inspectionhost forensics - Question #33Data Protection and Incident Response
An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed....
incident responseremediationpatchingroot cause analysis - Question #34Host Security and Management
What does the following WMIC command accomplish? process where name='malicious.exe' delete
WMICprocess managementmalware removalWindows CLI - Question #35Data Protection and Incident Response
An analyst wants to see a grouping of images that may be contained in a pcap file. Which tool natively meets this need?
pcap analysisnetwork forensicspacket capture toolsfile extraction - Question #36Defense-in-Depth and Security Architecture
Which of the following is considered a preventative control in operational security?
preventative controlsphysical securitycontrol classificationfire suppression - Question #37Data Protection and Incident Response
Which command is the Best choice for creating a forensic backup of a Linux system?
forensic imagingdd commandLinux forensicsevidence preservation - Question #38Enterprise Network Security and Network Services Security
Which of the following would be included in a router configuration standard?
router configurationACL namingnetwork standardsconfiguration management - Question #39Defense-in-Depth and Security Architecture
Requiring criminal and financial background checks for new employees is an example of what type of security control?
security controlsmanagement controlspersonnel securitybackground checks - Question #40Host Security and Management
You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexp...
rootkitdevice drivermalware analysisWindows kernel - Question #41Enterprise Network Security and Network Services Security
Which of the following applies to newer versions of IOS that decrease their attack surface?
IOS hardeningattack surface reductionrouter securitydefault configuration - Question #42Perimeter Security and Intrusion Detection
The security team wants to detect connections that can compromise credentials by sending them in plaintext across the wire. Which of the following rules should they enable on their...
IDS rulesTelnetplaintext credentialsSnort signatures - Question #43Host Security and Management
Which Windows tool would use the following command to view a process: process where name='suspect_malware.exe'list statistics
WMICWQL queriesWindows process managementhost forensics - Question #44Data Protection and Incident Response
Which of the following is an outcome of the initial triage during incident response?
incident responsetriagenetwork segmentationinitial response - Question #45Data Protection and Incident Response
Which of the following is the best way to establish and verify the integrity of a file before copying it during an investigation?
file integrityhashingforensic investigationchain of custody - Question #46Data Protection and Incident Response
What would the output of the following command help an incident handler determine? cscript manage-bde . wsf -status
BitLockerdisk encryptionmanage-bdeWindows encryption - Question #47Enterprise Network Security and Network Services Security
What information would the Wireshark filter in the screenshot list within the display window?
Wiresharkdisplay filterspacket analysisnetwork forensics - Question #48Host Security and Management
What are Browser Helper Objects (BHO)s used for?
Browser Helper ObjectsInternet Explorerbrowser extensionsBHO - Question #49Host Security and Management
What is needed to be able to use taskkill to end a process on remote system?
taskkillremote administrationWindows credentialsprocess management - Question #50Enterprise Network Security and Network Services Security
A compromised router is reconfigured by an attacker to redirect SMTP email traffic to the attacker's server before sending packets on to their intended destinations. Which IP heade...
TTLIP header analysisrouting anomaly detectionSMTP traffic - Question #51Host Security and Management
Which tool keeps a backup of all deleted items, so that they can be restored later if need be?
HijackThisbrowser hijackingmalware removal toolsWindows utilities