GCED Exam Questions
96 real GCED exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #52Defense-in-Depth and Security Architecture
Which statement below is the MOST accurate about insider threat controls?
insider threatinformation classificationsecurity controlsaccess management - Question #53Enterprise Network Security and Network Services Security
In penetration testing, what is the primary purpose of "pivoting"?
penetration testingpivotinglateral movementnetwork exploitation - Question #54Data Protection and Incident Response
What is the primary goal of "containment" in incident response?
incident responsecontainmentsystem isolationIR phases - Question #55Host Security and Management
During interactive malware analysis, what is the purpose of a sandbox environment?
sandboxdynamic malware analysisbehavioral analysiscontrolled environment - Question #57Cloud and Virtualization Security
In cloud-based infrastructure, what is the main responsibility of a Cloud Access Security Broker (CASB)?
CASBcloud securitycloud data protectioncloud access control - Question #58Perimeter Security and Intrusion Detection
When analyzing network flows, a sudden and unexplained increase in the number of outgoing ________ connections might indicate a security breach.
network flow analysisoutbound connectionsanomaly detectionbreach indicators - Question #59Host Security and Management
What does manual malware code reversal involve?
reverse engineeringdecompilationstatic malware analysismalware code analysis - Question #60Data Protection and Incident Response
_______ logs provide information about system and application errors, which can be valuable for diagnosing issues or identifying security incidents.
system logslog analysiserror loggingsecurity monitoring - Question #61Data Protection and Incident Response
At the start of an investigation on a Windows system, the lead handler executes the following commands after inserting a USB drive. What is the purpose of this command? C:\ >dir /...
Windows CLIdir command flagsforensic data collectionhidden file enumeration - Question #62Host Security and Management
Which of the following is a key advantage of disassembling malware code?
disassemblystatic analysismalware reverse engineeringmalware functionality - Question #63Perimeter Security and Intrusion Detection
When an IDS system looks for a pattern indicating a known worm, what type of detection method is it using?
signature-based detectionIDSpattern matchingworm detection - Question #64Data Protection and Incident Response
Why would an incident handler acquire memory on a system being investigated?
memory acquisitiondigital forensicsincident handlingvolatile data - Question #65Defense-in-Depth and Security Architecture
Which could be described as a Threat Vector?
threat vectorattack surfacevulnerabilityweb server security - Question #66Perimeter Security and Intrusion Detection
A security device processes the first packet from 10.62.34.12 destined to 10.23.10.7 and recognizes a malicious anomaly. The first packet makes it to 10.23.10.7 before the security...
active responseIDSTCP RSTnetwork security devices - Question #67Perimeter Security and Intrusion Detection
Which tool uses a Snort rules file for input and by design triggers Snort alerts?
SnortIDS testingNidsbenchintrusion detection tools - Question #68Enterprise Network Security and Network Services Security
Network administrators are often hesitant to patch the operating systems on CISCO router and switch operating systems, due to the possibility of causing network instability, mainly...
patch managementCisco IOSnetwork device hardeningnetwork stability - Question #69Defense-in-Depth and Security Architecture
A company estimates a loss of $2,374 per hour in sales if their website goes down. Their webserver hosting site's documented downtime was 7 hours each quarter over the last two yea...
annualized loss expectancyrisk quantificationALErisk management - Question #70Perimeter Security and Intrusion Detection
To detect worms and viruses buried deep within a network packet payload, Gigabytes worth of traffic content entering and exiting a network must be checked with which of the followi...
deep packet inspectionsignature matchingpayload analysisnetwork traffic inspection - Question #71Host Security and Management
When identifying malware, what is a key difference between a Worm and a Bot?
malware classificationbotwormC2 communication - Question #72Data Protection and Incident Response
The creation of a filesystem timeline is associated with which objective?
filesystem timelineforensic analysisdigital forensicsincident investigation - Question #73Data Protection and Incident Response
How does data classification help protect against data loss?
data classificationDLPdata loss preventiondata protection controls - Question #74Enterprise Network Security and Network Services Security
Enabling port security prevents which of the following?
port securityMAC floodingswitch securityDoS prevention - Question #75Perimeter Security and Intrusion Detection
How does an Nmap connect scan work?
NmapTCP connect scanport scanningTCP handshake - Question #76Perimeter Security and Intrusion Detection
When running a Nmap UDP scan, what would the following output indicate?
NmapUDP scanningopen|filtered statefirewall detection - Question #77Host Security and Management
Which of the following would be used in order to restrict software form performing unauthorized operations, such as invalid access to memory or invalid calls to system access?
application controlmemory protectionsoftware restrictionhost hardening - Question #78Perimeter Security and Intrusion Detection
What attack was indicated when the IDS system picked up the following text coming from the Internet to the web server? select user, password from user where user= "jdoe" and passwo...
SQL injectionweb application attackIDS detectionattack recognition - Question #79Perimeter Security and Intrusion Detection
What would be the output of the following Google search? filetype:doc inurl:ws_ftp
Google hackingOSINTinformation gatheringGoogle dork operators - Question #80Data Protection and Incident Response
What is the BEST sequence of steps to remove a bot from a system?
malware removalbot eradicationincident responseremediation sequence - Question #81Enterprise Network Security and Network Services Security
Which of the following is an SNMPv3 security feature that was not provided by earlier versions of the protocol?
SNMPv3AES encryptionSNMP securitynetwork protocol hardening - Question #82Host Security and Management
Which of the following is a major problem that attackers often encounter when attempting to develop or use a kernel mode rootkit?
kernel rootkitrootkit instabilityOS dependencymalware analysis - Question #83Host Security and Management
Which command tool can be used to change the read-only or hidden setting of the file in the screenshot?
attrib commandfile attributesWindows CLIhost management - Question #84Enterprise Network Security and Network Services Security
Which Unix administration tool is designed to monitor configuration changes to Cisco, Extreme and Foundry infrastructure devices?
RANCIDnetwork device configuration monitoringCisco infrastructureconfiguration management - Question #85Enterprise Network Security and Network Services Security
If a Cisco router is configured with the "service config" configuration statement, which of the following tools could be used by an attacker to apply a new router configuration?
TFTPCisco service confignetwork device attackrouter misconfiguration - Question #86Defense-in-Depth and Security Architecture
Who is ultimately responsible for approving methods and controls that will reduce any potential risk to an organization?
risk managementgovernanceorganizational rolessecurity policy approval - Question #87Perimeter Security and Intrusion Detection
An internal host at IP address 10.10.50.100 is suspected to be communicating with a command and control whenever a user launches browser window. What features and settings of Wires...
Wiresharkpacket filteringC2 communicationtraffic analysis - Question #88Defense-in-Depth and Security Architecture
Michael, a software engineer, added a module to a banking customer's code. The new module deposits small amounts of money into his personal bank account. Michael has access to edit...
social engineeringinsider threatmalicious code injectionsoftware supply chain - Question #89Enterprise Network Security and Network Services Security
A company wants to allow only company-issued devices to attach to the wired and wireless networks. Additionally, devices that are not up-to-date with OS patches need to be isolated...
802.1xNetwork Access Controldevice authenticationpatch compliance enforcement - Question #90Data Protection and Incident Response
When attempting to collect data from a suspected system compromise, which of the following should generally be collected first?
order of volatilitymemory forensicsincident responselive acquisition - Question #91Data Protection and Incident Response
Before re-assigning a computer to a new employee, what data security technique does the IT department use to make sure no data is left behind by the previous user?
data wipingmedia sanitizationdata remanenceendpoint data security - Question #92Data Protection and Incident Response
Monitoring the transmission of data across the network using a man-in-the-middle attack presents a threat against which type of data?
man-in-the-middledata in transitnetwork interceptiondata classification - Question #93Data Protection and Incident Response
Which type of media should the IR team be handling as they seek to understand the root cause of an incident?
forensic evidence handlingIR mediaworking copyincident response procedures - Question #94Data Protection and Incident Response
An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then remove...
worm propagationIPS signatureincident eradicationIR failure analysis - Question #95Data Protection and Incident Response
A legacy server on the network was breached through an OS vulnerability with no patch available. The server is used only rarely by employees across several business units. The thef...
data classificationsecurity control failurelegacy systemsundetected breach - Question #96Enterprise Network Security and Network Services Security
Analyze the screenshot below. Which of the following attacks can be mitigated by these configuration settings?
MAC floodingport securityswitch securitylayer 2 attacks - Question #97Data Protection and Incident Response
Of the following pieces of digital evidence, which would be collected FIRST from a live system involved in an incident?
order of volatilityswap spacelive forensicsvolatile data collection - Question #98Perimeter Security and Intrusion Detection
Which of the following attacks would use ".." notation as part of a web request to access restricted files and directories, and possibly execute code on the web server?
directory traversalpath traversalweb application securityURL manipulation