GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 3 of 9.
- Question #101
When discussing access controls, which of the following terms describes the process of determining the activities or functions that an Individual is permitted to perform?
- Question #102
Which command would allow an administrator to determine if a RPM package was already installed?
- Question #103
A new data center is being built where customer credit information will be processed and stored. Which of the following actions will help maintain the confidentiality of the data?
- Question #104
In order to capture traffic for analysis, Network Intrusion Detection Systems (NIDS) operate with network cards in what mode?
- Question #105
A Host-based Intrusion Prevention System (HIPS) software vendor records how the Firefox Web browser interacts with the operating system and other applications, and identifies all a...
- Question #106
If you do NOT have an original file to compare to, what is a good way to identify steganography in potential carrier files?
- Question #107
You ask your system administrator to verify user compliance with the corporate policies on password strength, namely that all passwords will have at least one numeral, at least one...
- Question #108
Which of the following SIP INVITE lines indicates to the remote registrar the VoIP phone that initiated the call?
- Question #109
Which access control mechanism requires a high amount of maintenance since all data must be classified, and all users granted appropriate clearance?
- Question #110
When are Group Policy Objects (GPOs) NOT applied automatically to workstations?
- Question #111
Against policy, employees have installed Peer-to-Peer applications on their workstations and they are using them over TCP port 80 to download files via the company network from oth...
- Question #112
When considering ingress filtering, why should all inbound packets be dropped if they contain a source address from within the protected network address space? (A) The packets are...
- Question #113
What is the maximum passphrase length in Windows 2000/XP/2003?
- Question #114
The previous system administrator at your company used to rely heavily on email lists, such as vendor lists and Bug Traq to get information about updates and patches. While a usefu...
- Question #115
Which of the following is NOT typically used to mitigate the war dialing threat?
- Question #116
When Net Stumbler is initially launched, it sends wireless frames to which of the following addresses?
- Question #117
Which of the following attack vectors are addressed by Xinetd and TCP Wrappers? (A) Outsider attack from network (B) Outsider attack from a telephone (C) Insider attack from local...
- Question #118
Your system has been infected by malware. Upon investigation, you discover that the malware propagated primarily via email. The malware attacked known vulnerabilities for which pat...
- Question #119
What is the term for a game in which for every win there must be an equivalent loss?
- Question #120
Your CIO has found out that it is possible for an attacker to clone your company's RFID (Radio Frequency ID) based key cards. The CIO has tasked you with finding a way to ensure th...
- Question #121
How often is session information sent to the web server from the browser once the session information has been established?
- Question #122
Where could you go in Windows XP/2003 to configure Automatic Updates?
- Question #123
What is the most secure way to address an unused Windows service so it cannot be exploited by malware?
- Question #124
What is the key difference between Electronic Codebook mode and other block cipher modes like Cipher Block Chaining, Cipher-Feedback and Output-Feedback?
- Question #125
Which of the following TCP packet flags indicates that host should IMMEDIATELY terminate the connection containing the packet?
- Question #126
To be considered a strong algorithm, an encryption algorithm must be which of the following?
- Question #127
In PKI, when someone wants to verify that the certificate is valid, what do they use to decrypt the signature?
- Question #128
What defensive measure could have been taken that would have protected the confidentiality of files that were divulged by systems that were compromised by malware?
- Question #129
The Windows 'tracert' begins by sending what type of packet to the destination host?
- Question #130
You are examining a packet capture session in Wire shark and see the packet shown in the accompanying image. Based on what you see, what is the appropriate protection against this...
- Question #131
What is SSL primarily used to protect you against?
- Question #132
The process of enumerating all hosts on a network defines which of the following activities?
- Question #133
Why are false positives such a problem with IPS technology?
- Question #134
For most organizations, which of the following should be the highest priority when it comes to physical security concerns?
- Question #135
If the NET_ID of the source and destination address in an IP (Internet Protocol) packet match, which answer BEST describes the routing method the sending host will use?
- Question #136
In addition to securing the operating system of production honey pot hosts, what is recommended to prevent the honey pots from assuming the identities of production systems that co...
- Question #137
What is the maximum number of connections a normal Bluetooth device can handle at one time?
- Question #138
What are the two actions the receiver of a PGP email message can perform that allows establishment of trust between sender and receiver?
- Question #139
An employee attempting to use your wireless portal reports receiving the error shown below. Which scenario is occurring?
- Question #140
Where is the source address located in an IPv4 header?
- Question #141
Which of the following are examples of Issue-Specific policies all organizations should address?
- Question #142
Which Host-based IDS (HIDS) method of log monitoring utilizes a list of keywords or phrases that define the events of interest for the analyst, then takes a list of keywords to wat...
- Question #143
What is a security feature available with Windows Vista and Windows 7 that was not present in previous Windows operating systems?
- Question #144
While using Wire shark to investigate complaints of users being unable to login to a web application, you come across an HTTP POST submitted through your web application. The conte...
- Question #145
It is possible to sniff traffic from other hosts on a switched Ethernet network by impersonating which type of network device?
- Question #146
Which of the following is TRUE regarding Ethernet?
- Question #147
Which of the following proxy servers provides administrative controls over the content?
- Question #148
Where are user accounts and passwords stored in a decentralized privilege management environment?
- Question #149
John works as a professional Ethical Hacker. He is assigned a project to test the security of Which of the following statements are true about rootkits? Each correct answer represe...
- Question #150
Which of the following statements about the integrity concept of information security management are true? Each correct answer represents a complete solution. Choose three.