GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 1 of 9.
- Question #1Penetration Testing Foundations & Reconnaissance
Your organization has broken its network into several sections/segments, which are separated by firewalls, ACLs and VLANs. The purpose is to defend segments of the network from pot...
network segmentationprotected enclavesdefense-in-depthVLAN - Question #2Cloud & Pivoting Techniques
Which of the following systems acts as a NAT device when utilizing VMware in NAT mode?
VMwareNAT modevirtualizationvirtual networking - Question #3Penetration Testing Foundations & Reconnaissance
Your organization is developing a network protection plan. No single aspect of your network seems more important than any other. You decide to avoid separating your network into se...
uniform protectiondefense-in-depthnetwork designsecurity architecture - Question #4Penetration Testing Foundations & Reconnaissance
When a packet leaving the network undergoes Network Address Translation (NAT), which of the following is changed?
NATsource address translationTCP/IPnetwork addressing - Question #5Reporting & Remediation
Which of the following elements is the most important requirement to ensuring the success of a business continuity plan?
business continuityBCPexecutive buy-inrisk management - Question #6Penetration Testing Foundations & Reconnaissance
Which of the following TCP dump output lines indicates the first step in the TCP 3-way handshake?
TCP three-way handshaketcpdumpSYN flagpacket analysis - Question #7Penetration Testing Foundations & Reconnaissance
Users at the Marketing department are receiving their new Windows XP Professional workstations. They will need to maintain local work files in the first logical volume, and will us...
NTFSFAT32Windows file systemaccess control - Question #8Penetration Testing Foundations & Reconnaissance
Which of the following is a new Windows Server 2008 feature for the Remote Desktop Protocol (RDP)?
RDPWindows Server 2008RemoteAppremote desktop - Question #9Penetration Testing Foundations & Reconnaissance
What is TRUE about Workgroups and Domain Controllers?
Windows domainsworkgroupdomain controllerActive Directory - Question #10Penetration Testing Foundations & Reconnaissance
What file instructs programs like Web spiders NOT to search certain areas of a site?
robots.txtweb crawlingOSINTpassive reconnaissance - Question #11Exploitation & Post-Exploitation Techniques
Which of the following is a benefit of using John the Ripper for auditing passwords?
John the Ripperpassword crackingMD5password auditing - Question #12Penetration Testing Foundations & Reconnaissance
Which of the following is an advantage of a Host Intrusion Detection System (HIDS) versus a Network Intrusion Detection System (NIDS)?
HIDSNIDSintrusion detectionencrypted traffic - Question #13Networking and Core Concepts
Which of the following is more commonly used for establishing high-speed backbones that interconnect smaller networks and can carry signals over significant distances?
ATMbackbone networksWAN technologiesnetwork topology - Question #14Linux and Cryptography
The Linux command to make the /etc/shadow file, already owned by root, readable only by root is which of the following?
chmodfile permissions/etc/shadowLinux hardening - Question #15Linux and Cryptography
What is the main reason that DES is faster than RSA?
DESRSAsymmetric cryptographyasymmetric cryptography - Question #16Incident Handling, Risk, and Governance
Which of the following statements would be seen in a Disaster Recovery Plan?
disaster recovery planalternate siteBCPrestoration objectives - Question #17Operating System Security
Your software developer comes to you with an application that controls a user device. The application monitors its own behavior and that of the device and creates log files. The lo...
Linux filesystem hierarchy/var/loglog file storageFHS - Question #18Network Security
Which of the following is an advantage of private circuits versus VPNs?
private circuitsVPNperformance guaranteesWAN comparison - Question #19Network Security
What would the following IP tables command do? IP tables -I INPUT -s 99.23.45.1/32 -j DROP
iptablespacket filteringfirewall rulessource IP blocking - Question #20Linux and Cryptography
What would the file permission example "rwsr-sr-x" translate to in absolute mode?
setuidsetgidoctal permissionsspecial permission bits - Question #21Operating System Security
Which of the following Unix syslog message priorities is the MOST severe?
sysloglog severity levelsemergUnix logging - Question #22Incident Handling, Risk, and Governance
During a scheduled evacuation training session the following events took place in this order: 1. Evacuation process began by triggering the building fire alarm. 2a. The meeting poi...
physical securityevacuation proceduressafety rolesincident response - Question #23Windows and Malware
What type of malware is a self-contained program that has the ability to copy itself without parasitically infecting other host code?
wormmalware classificationself-replicating codemalware types - Question #24Incident Handling, Risk, and Governance
An IT security manager is trying to quickly assess the risks associated with not implementing a corporate firewall system. What sort of risk assessment is most appropriate?
qualitative risk assessmentrisk managementfirewallrisk assessment types - Question #25Networking and Core Concepts
In a /24 subnet, which of the following is a valid broadcast address?
broadcast address/24 subnetIPv4 addressingsubnetting - Question #26Networking and Core Concepts
Which of the following applications would be BEST implemented with UDP instead of TCP?
UDPTCPmulticaststreaming protocols - Question #27Incident Handling, Risk, and Governance
One of your Linux systems was compromised last night. According to change management history and a recent vulnerability scan, the system's patches were up-to-date at the time of th...
zero-day exploitpatch managementvulnerability analysisincident analysis - Question #28Access Control and Password Management
A folder D:\Files\Marketing has the following NTFS permissions: - Administrators: Full Control - Marketing: Change and Authenticated - Users: Read It has been shared on the server...
NTFS permissionsshare permissionseffective permissionsWindows access control - Question #29Defense in Depth and Protocols
Which of the following fields CANNOT be hashed by Authentication Header (AH) in transport mode?
IPsecAuthentication Headermutable fieldsTTL - Question #30Network Security
Which of the following is an advantage of an Intrusion Detection System?
IDSintrusion detectionsecurity tool evaluationnetwork security - Question #31Operating System Security
If Linux server software is a requirement in your production environment which of the following should you NOT utilize?
Linux distributionsCygwinserver OS selectionproduction environment - Question #32Network Security
Which of the following statements best describes where a border router is normally placed?
border routernetwork topologyfirewall placementperimeter security - Question #33Networking and Core Concepts
following is likely to provide an Authoritative reply?
DNSauthoritative DNSDNS hierarchyname resolution - Question #34Network Security
You are reviewing a packet capture file from your network intrusion detection system. In the packet stream, you come across a long series of "no operation" (NOP) commands. In addit...
NOP sledbuffer overflowpacket analysisintrusion detection - Question #35Linux and Cryptography
When should you create the initial database for a Linux file integrity checker?
file integritybaseline databasetripwireLinux hardening - Question #36Incident Handling, Risk, and Governance
Validating which vulnerabilities in a network environment are able to be exploited by an attacker is called what?
vulnerability scanningpenetration testingsecurity assessmentexploit validation - Question #37Incident Handling, Risk, and Governance
Which of the following statements would describe the term "incident" when used in the branch of security known as Incident Handling? (A) Any observable network event (B) Harm to sy...
incident definitionincident handlingsecurity eventsthreat classification - Question #38Incident Handling, Risk, and Governance
Which of the following is the FIRST step in performing an Operational Security (OP5EC) Vulnerabilities Assessment?
OPSECvulnerability assessmentcritical informationrisk management - Question #39Networking and Core Concepts
Which of the following SIP methods is used to setup a new session and add a caller?
SIPVoIPINVITE methodsession initiation - Question #40Network Security
You are an Intrusion Detection Analyst and the system has alerted you to an Event of Interest (EOI) that appears to be activity generated by a worm. You investigate and find that t...
IDSfalse positivealert categorizationintrusion detection - Question #41Operating System Security
Which aspect of UNIX systems was process accounting originally developed for?
process accountingUNIX historytime sharingaudit logging - Question #42Network Security
IPS devices that are classified as "In-line NIDS" devices use a combination of anomaly analysis, signature-based rules, and what else to identify malicious events on the network?
IPSin-line NIDSapplication analysisintrusion prevention - Question #43Windows and Malware
What is the name of the registry key that is used to manage remote registry share permissions for the whole registry?
Windows registrywinregremote registryregistry permissions - Question #44Networking and Core Concepts
Which layer of the TCP/IP Protocol Stack Is responsible for port numbers?
TCP/IPtransport layerport numbersprotocol stack - Question #45Windows and Malware
How are differences in configuration settings handled between Domain and Local Group Policy Objects (GPOs)?
Group PolicyGPO precedencedomain policylocal policy - Question #46Access Control and Password Management
An attacker gained physical access to an internal computer to access company proprietary data. The facility is protected by a fingerprint biometric system that records both failed...
biometricsFalse Accept RateFARphysical access control - Question #47Defense in Depth and Protocols
Which of the following is a type of countermeasure that can be deployed to ensure that a threat vector does not meet a vulnerability?
prevention controlscountermeasuresthreat mitigationsecurity controls - Question #48Defense in Depth and Protocols
What is the main problem with relying solely on firewalls to protect your company's sensitive data?
firewall limitationsdefense in depthfirewall bypasslayered security - Question #49Windows and Malware
Which of the following features of Windows 7 allows an administrator to both passively review installed software and configure policies to prevent out-of-date or insecure software...
AppLockersoftware restrictionapplication controlWindows 7 - Question #50Network Security
What does an attacker need to consider when attempting an IP spoofing attack that relies on guessing Initial Sequence Numbers (ISNs)?
IP spoofingTCP sequence numbersISN guessingsession hijacking