GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 3 of 9.
- Question #101Access Control and Password Management
When discussing access controls, which of the following terms describes the process of determining the activities or functions that an Individual is permitted to perform?
authorizationaccess controlauthentication vs authorizationIAM - Question #102Linux and Cryptography
Which command would allow an administrator to determine if a RPM package was already installed?
RPMpackage managementLinux commandssoftware inventory - Question #103Defense in Depth and Protocols
A new data center is being built where customer credit information will be processed and stored. Which of the following actions will help maintain the confidentiality of the data?
data confidentialityphysical access controldata center securityPCI DSS - Question #104Network Security
In order to capture traffic for analysis, Network Intrusion Detection Systems (NIDS) operate with network cards in what mode?
promiscuous modeNIDSpacket capturenetwork monitoring - Question #105Defense in Depth and Protocols
A Host-based Intrusion Prevention System (HIPS) software vendor records how the Firefox Web browser interacts with the operating system and other applications, and identifies all a...
HIPSapplication behavior monitoringintrusion preventionbehavioral analysis - Question #106Incident Handling, Risk, and Governance
If you do NOT have an original file to compare to, what is a good way to identify steganography in potential carrier files?
steganographystatistical analysiscarrier file detectionforensics - Question #107Access Control and Password Management
You ask your system administrator to verify user compliance with the corporate policies on password strength, namely that all passwords will have at least one numeral, at least one...
password policyoffline crackingcompliance testingpassword complexity - Question #108Networking and Core Concepts
Which of the following SIP INVITE lines indicates to the remote registrar the VoIP phone that initiated the call?
SIPVoIPINVITE messageUser-Agent header - Question #109Access Control and Password Management
Which access control mechanism requires a high amount of maintenance since all data must be classified, and all users granted appropriate clearance?
mandatory access controldata classificationsecurity clearanceMAC vs DAC - Question #110Windows and Malware
When are Group Policy Objects (GPOs) NOT applied automatically to workstations?
Group Policy ObjectsGPOWindows policyActive Directory - Question #111Network Security
Against policy, employees have installed Peer-to-Peer applications on their workstations and they are using them over TCP port 80 to download files via the company network from oth...
firewall subversionport 80 tunnelingP2P applicationspolicy violation - Question #112Network Security
When considering ingress filtering, why should all inbound packets be dropped if they contain a source address from within the protected network address space? (A) The packets are...
ingress filteringIP spoofingsource address validationpacket filtering - Question #113Access Control and Password Management
What is the maximum passphrase length in Windows 2000/XP/2003?
Windows passphrasepassword lengthWindows XPauthentication - Question #114Operating System Security
The previous system administrator at your company used to rely heavily on email lists, such as vendor lists and Bug Traq to get information about updates and patches. While a usefu...
patch managementautomated updatesapt-getproduction systems - Question #115Network Security
Which of the following is NOT typically used to mitigate the war dialing threat?
war dialingmodem securitydial-up attackcountermeasures - Question #116Networking and Core Concepts
When Net Stumbler is initially launched, it sends wireless frames to which of the following addresses?
NetStumblerwireless scanningbroadcast address802.11 - Question #117Network Security
Which of the following attack vectors are addressed by Xinetd and TCP Wrappers? (A) Outsider attack from network (B) Outsider attack from a telephone (C) Insider attack from local...
TCP Wrappersxinetdnetwork access controlservice filtering - Question #118Windows and Malware
Your system has been infected by malware. Upon investigation, you discover that the malware propagated primarily via email. The malware attacked known vulnerabilities for which pat...
malware propagationemail securityattachment scanningemail server - Question #119Incident Handling, Risk, and Governance
What is the term for a game in which for every win there must be an equivalent loss?
zero-sumrisk terminologygame theorysecurity concepts - Question #120Access Control and Password Management
Your CIO has found out that it is possible for an attacker to clone your company's RFID (Radio Frequency ID) based key cards. The CIO has tasked you with finding a way to ensure th...
RFID cloningtwo-factor authenticationphysical accesssmart card - Question #121Cloud, Web, and Application Security
How often is session information sent to the web server from the browser once the session information has been established?
session managementweb sessionscookiesHTTP requests - Question #122Operating System Security
Where could you go in Windows XP/2003 to configure Automatic Updates?
Windows XPAutomatic UpdatesControl Panelpatch management - Question #123Windows and Malware
What is the most secure way to address an unused Windows service so it cannot be exploited by malware?
Windows servicesattack surface reductionhardeningmalware defense - Question #124Linux and Cryptography
What is the key difference between Electronic Codebook mode and other block cipher modes like Cipher Block Chaining, Cipher-Feedback and Output-Feedback?
ECB modeblock cipher modesCBCpattern concealment - Question #125Networking and Core Concepts
Which of the following TCP packet flags indicates that host should IMMEDIATELY terminate the connection containing the packet?
TCP flagsRSTconnection terminationTCP - Question #126Linux and Cryptography
To be considered a strong algorithm, an encryption algorithm must be which of the following?
Kerckhoffs principlecryptographic strengthopen algorithmsecurity by obscurity - Question #127Linux and Cryptography
In PKI, when someone wants to verify that the certificate is valid, what do they use to decrypt the signature?
PKIdigital certificateCA public keycertificate verification - Question #128Defense in Depth and Protocols
What defensive measure could have been taken that would have protected the confidentiality of files that were divulged by systems that were compromised by malware?
file encryptionencryption at restdata confidentialitymalware defense - Question #129Networking and Core Concepts
The Windows 'tracert' begins by sending what type of packet to the destination host?
tracertTTLUDPICMP - Question #130Network Security
You are examining a packet capture session in Wire shark and see the packet shown in the accompanying image. Based on what you see, what is the appropriate protection against this...
Smurf attackIP directed broadcastDDoSpacket analysis - Question #131Defense in Depth and Protocols
What is SSL primarily used to protect you against?
SSLTLSeavesdroppingencryption in transit - Question #132Networking and Core Concepts
The process of enumerating all hosts on a network defines which of the following activities?
network mappinghost enumerationnetwork discoveryreconnaissance - Question #133Network Security
Why are false positives such a problem with IPS technology?
IPSfalse positivessignature rulesintrusion prevention - Question #134Incident Handling, Risk, and Governance
For most organizations, which of the following should be the highest priority when it comes to physical security concerns?
physical securityemployee safetyrisk prioritiesaccess control - Question #135Networking and Core Concepts
If the NET_ID of the source and destination address in an IP (Internet Protocol) packet match, which answer BEST describes the routing method the sending host will use?
IP routingNET_IDlocal routingsubnet - Question #136Network Security
In addition to securing the operating system of production honey pot hosts, what is recommended to prevent the honey pots from assuming the identities of production systems that co...
honeypotdeception technologyaddress spaceDoS prevention - Question #137Networking and Core Concepts
What is the maximum number of connections a normal Bluetooth device can handle at one time?
Bluetoothpiconetwireless connectionsdevice limits - Question #138Linux and Cryptography
What are the two actions the receiver of a PGP email message can perform that allows establishment of trust between sender and receiver?
PGPasymmetric encryptiondigital signaturekey decryption - Question #139Network Security
An employee attempting to use your wireless portal reports receiving the error shown below. Which scenario is occurring?
evil twinrogue access pointwireless interceptionMITM - Question #140Networking and Core Concepts
Where is the source address located in an IPv4 header?
IPv4 headerpacket structuresource address offsetbyte offset - Question #141Incident Handling, Risk, and Governance
Which of the following are examples of Issue-Specific policies all organizations should address?
issue-specific policyacceptable usebackup policysecurity governance - Question #142Network Security
Which Host-based IDS (HIDS) method of log monitoring utilizes a list of keywords or phrases that define the events of interest for the analyst, then takes a list of keywords to wat...
HIDSlog monitoringinclusive analysiskeyword matching - Question #143Windows and Malware
What is a security feature available with Windows Vista and Windows 7 that was not present in previous Windows operating systems?
UACUser Account ControlWindows VistaOS security features - Question #144Cloud, Web, and Application Security
While using Wire shark to investigate complaints of users being unable to login to a web application, you come across an HTTP POST submitted through your web application. The conte...
SQL injectioninput sanitizationweb application securityWireshark - Question #145Network Security
It is possible to sniff traffic from other hosts on a switched Ethernet network by impersonating which type of network device?
ARP spoofingswitched network sniffingrouter impersonationtraffic interception - Question #146Networking and Core Concepts
Which of the following is TRUE regarding Ethernet?
Ethernetshared mediaCSMA/CDcollision domain - Question #147Network Security
Which of the following proxy servers provides administrative controls over the content?
proxy servercontent filteringweb filteringadministrative controls - Question #148Access Control and Password Management
Where are user accounts and passwords stored in a decentralized privilege management environment?
decentralized authenticationprivilege managementlocal account storagepassword management - Question #149Windows and Malware
John works as a professional Ethical Hacker. He is assigned a project to test the security of Which of the following statements are true about rootkits? Each correct answer represe...
rootkitbackdoorTrojanpacket sniffer - Question #150Incident Handling, Risk, and Governance
Which of the following statements about the integrity concept of information security management are true? Each correct answer represents a complete solution. Choose three.
data integrityCIA triadunauthorized modificationinformation security management