GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 2 of 9.
- Question #51Incident Handling, Risk, and Governance
In preparation to do a vulnerability scan against your company's systems. You've taken the steps below: - You've notified users that there will be a system test. - You've priontize...
vulnerability scanningscan authorizationsecurity testingpre-scan preparation - Question #52Access Control and Password Management
There are three key factors in selecting a biometric mechanism. What are they?
biometricsreliabilityuser acceptancebiometric selection - Question #53Networking and Core Concepts
What is the following sequence of packets demonstrating?
TCP teardownFIN packetsconnection terminationpacket analysis - Question #54Networking and Core Concepts
Which of the following is a Layer 3 device that will typically drop directed broadcast traffic?
Layer 3 devicesdirected broadcastroutersnetwork layers - Question #55Operating System Security
Which of the following would be a valid reason to use a Windows workgroup?
Windows workgroupdomain vs workgroupnetwork administrationWindows configuration - Question #56Defense in Depth and Protocols
Which Defense-in-Depth model involves identifying various means by which threats can become manifest and providing security mechanisms to shut them down?
defense in depththreat vectorsvector-oriented defensesecurity models - Question #57Operating System Security
Included below is the output from a resource kit utility run against local host. Which command could have produced this output?
Windows commandstasklistprocess enumerationresource kit - Question #58Network Security
How is a Distributed Denial of Service (DDOS) attack distinguished from a regular DOS attack?
DDoSDoS attackdistributed attacknetwork attacks - Question #59Networking and Core Concepts
Regarding the UDP header below, what is the length in bytes of the UDP datagrarn? 04 1a 00 a1 00 55 db 51
UDP headerprotocol analysishex decodingdatagram length - Question #60Defense in Depth and Protocols
A sensor that uses a light beam and a detecting plate to alarm if the light beam is obstructed is most commonly used to identify which of the following threats?
physical securitysmoke detectionphotoelectric sensorenvironmental threats - Question #61Networking and Core Concepts
What protocol is a WAN technology?
WAN protocolsFrame RelayWAN technologiesnetwork types - Question #62Linux and Cryptography
Which of the following is a characteristic of hash operations?
hash functionscryptographyone-way functionsmessage digest - Question #63Networking and Core Concepts
The TTL can be found in which protocol header?
IP headerTTLprotocol headersIP protocol - Question #64Network Security
Which of the following is a required component for successful 802.lx network authentication?
802.1xnetwork authenticationsupplicantNAC - Question #65Windows and Malware
What is the name of the command-line tool for Windows that can be used to manage audit policies on remote systems?
AUDITPOLWindows audit policyWindows administrationsecurity auditing - Question #66Cloud, Web, and Application Security
Many IIS servers connect to Microsoft SQL databases. Which of the following statements about SQL server security is TRUE?
SQL injectionSQL Server securityweb application securityIIS security - Question #67Incident Handling, Risk, and Governance
You have an automated system for patching the operating systems of all your computers. All patches are supposedly current. Yet your automated vulnerability scanner has just reporte...
vulnerability scanningpatch managementfalse positivessecurity verification - Question #68Windows and Malware
You are doing some analysis of malware on a Unix computer in a closed test network. The IP address of the computer is 192.168.1.120. From a packet capture, you see the malware is a...
HOSTS fileDNS resolutionmalware analysisnetwork redirection - Question #69Incident Handling, Risk, and Governance
What type of formal document would include the following statement? Employees are responsible for exercising good judgment regarding the reasonableness of personal use. Individual...
acceptable use policysecurity policygovernanceinternet use - Question #70Windows and Malware
What is the command-line tool for Windows XP and later that allows administrators the ability to get or set configuration data for a very wide variety of computer and user account...
WMICWindows administrationWMIcommand-line tools - Question #71Incident Handling, Risk, and Governance
A US case involving malicious code is brought to trial. An employee had opened a helpdesk ticket to report specific instances of strange behavior on her system. The IT helpdesk rep...
digital forensicsincident responselegal proceedingschain of custody - Question #72Access Control and Password Management
When you log into your Windows desktop what information does your Security Access Token (SAT) contain?
Windows security tokenaccess tokenSIDsWindows authentication - Question #73Incident Handling, Risk, and Governance
Which type of risk assessment results are typically categorized as low, medium, or high-risk events?
risk assessmentqualitative analysisrisk categorizationrisk levels - Question #74Incident Handling, Risk, and Governance
What is the first thing that should be done during the containment step of incident handling?
incident responsecontainmentincident handlingfirst response - Question #75Network Security
Which choice best describes the line below? alert tcp any any -> 192.168.1.0/24 80 (content: /cgi-bin/test.cgi"; msg: "Attempted CGI-BIN Access!!";)
Snort rulesIDS signaturesCGI attack detectionnetwork monitoring - Question #76Network Security
Which class of IDS events occur when the IDS fails to alert on malicious data?
IDSfalse negativeintrusion detectiondetection accuracy - Question #77Windows and Malware
Which of the following tools is also capable of static packet filtering?
Windows toolspacket filteringIPsecipsecpol - Question #78Linux and Cryptography
Which of the following best describes the level of risk associated with using proprietary crypto algorithms.?
cryptographyproprietary algorithmspublic scrutinyencryption risk - Question #79Incident Handling, Risk, and Governance
What is the discipline of establishing a known baseline and managing that condition known as?
configuration managementbaselinesecurity managementchange control - Question #80Windows and Malware
What is the name of the Windows XP/2003 tool that you can use to schedule commands to be executed on remote systems during off-peak hours?
Windows toolstask schedulingSCHTASKSremote administration - Question #81Incident Handling, Risk, and Governance
Your IT security team is responding to a denial of service attack against your server. They have taken measures to block offending IP addresses. Which type of threat control is thi...
DoS attackcorrective controlsincident responsethreat control types - Question #82Incident Handling, Risk, and Governance
What is the unnoticed theft of sensitive data from a laptop owned by an organization's CEO an example of in information warfare?
information warfaresymmetric warfaredata theftCEO threat - Question #83Incident Handling, Risk, and Governance
Who is responsible for deciding the appropriate classification level for data within an organization?
data classificationdata ownersecurity rolesinformation governance - Question #84Defense in Depth and Protocols
Which of the following protocols describes the operation of security In H.323?
H.323VoIP securityH.235protocol security - Question #85Networking and Core Concepts
If a DNS client wants to look up the IP address for good.news.com and does not receive an authoritative reply from its local DNS server, which name server is most likely to provide...
DNSauthoritative serverdomain resolutionDNS hierarchy - Question #86Windows and Malware
Analyze the screenshot below. What is the purpose of this message?
malware alertssocial engineeringbrowser warningsmalicious software - Question #87Network Security
Why would someone use port 80 for deployment of unauthorized services?
port 80firewall evasioncovert channelsunauthorized services - Question #88Incident Handling, Risk, and Governance
Which of the below choices should an organization start with when implementing an effective risk management process?
risk managementsecurity policygovernancerisk framework - Question #89Networking and Core Concepts
In trace route results, what is the significance of an * result?
traceroutenetwork diagnosticsICMPhop timeout - Question #90Networking and Core Concepts
You have set up a local area network for your company. Your firewall separates your network into several sections: a DMZ with semi-public servers (web, dns, email) and an intranet...
network switcheshubspacket sniffingnetwork segmentation - Question #91Incident Handling, Risk, and Governance
The following three steps belong to the chain of custody for federal rules of evidence. What additional step is recommended between steps 2 and 3? STEP 1 - Take notes: who, what, w...
chain of custodydigital forensicsMD5 checksumevidence integrity - Question #92Defense in Depth and Protocols
Which Defense-in-Depth principle starts with an awareness of the value of each section of information within an organization?
defense in depthinformation-centric securitysecurity strategydata value - Question #93Linux and Cryptography
Which of the following Linux commands can change both the username and group name a file belongs to?
chownchgrpfile permissionsLinux commands - Question #94Incident Handling, Risk, and Governance
Which of the following is a backup strategy?
backup strategydifferential backupdata recovery - Question #95Incident Handling, Risk, and Governance
The Return on Investment (ROI) measurement used in Information Technology and Information Security fields is typically calculated with which formula?
ROIsecurity investmentrisk metricscost-benefit - Question #96Networking and Core Concepts
What database can provide contact information for Internet domains?
WHOISdomain registrationDNS reconnaissanceinternet registry - Question #97Linux and Cryptography
During which of the following steps is the public/private key-pair generated for Public Key Infrastructure (PKI)?
PKIkey pair generationpublic key infrastructurecertificate lifecycle - Question #98Operating System Security
What is the process of simultaneously installing an operating system and a Service Pack called?
slipstreamingOS installationservice packpatch management - Question #99Networking and Core Concepts
Which of the following is an UDP based protocol?
UDPSNMPtransport protocolsnetwork protocols - Question #100Networking and Core Concepts
What is the function of the TTL (Time to Live) field in IPv4 and the Hop Limit field in IPv6 In an IP Packet header?
TTLhop limitIPv4IPv6 packet header