GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 6 of 9.
- Question #251Windows and Malware
To update from a Windows Server Update Services (WSUS) server, users of the machine must have what rights, If any?
WSUSWindows updatespatch managementlocal administrator - Question #252Windows and Malware
How many clients Is a single WSUS server designed to support when the minimum system requirements are met?
WSUSpatch managementsystem requirementsclient capacity - Question #253Defense in Depth and Protocols
What does Authentication Header (AH) add to the packet in order to prevent an attacker from lying about the source?
IPSecAuthentication HeaderIntegrity Check Valuepacket integrity - Question #254Access Control and Password Management
What is needed for any of the four options for Azure AD multi-factor user authentication?
Azure ADmulti-factor authenticationMFAcloud identity - Question #255Network Security
A Network Engineer is charged with maintaining and protecting a network with a high availability requirement. In addition to other defenses, they have chosen to implement a NIPS. H...
NIPSfail-openhigh availabilityIPS configuration - Question #256Defense in Depth and Protocols
How is confidentiality disabled in the IPSec Encapsulated Security Payload protocol?
IPSecESPNULL encryptionconfidentiality - Question #257Operating System Security
What Windows log should be checked to troubleshoot a Windows service that is falling to start?
Windows Event LogSystem logservice troubleshootingEvent Viewer - Question #258Cloud, Web, and Application Security
Which Terraform command should be run immediately after creating a new configuration file for a cloud-based virtual machine?
TerraformIaCcloud provisioningterraform init - Question #259Cloud, Web, and Application Security
Which of the following would be used to explicitly deny the traffic from a foreign IP address scanning the EC2 Instances in a VPC?
AWSSecurity GroupsVPCtraffic filtering - Question #260Networking and Core Concepts
What does it mean if a protocol such as HTTP is stateless?
HTTPstateless protocolweb protocolssession management - Question #261Operating System Security
On an NTFS file system, what will happen when a conflict exists between Allow and Deny permissions?
NTFSfile permissionsACLDeny precedence - Question #262Incident Handling, Risk, and Governance
What improvement could a company that is rated at a NIST Implementation Tier of 2: Risk Informed do to Increase their rating to a Tier 3: Repeatable?
NIST Cybersecurity Frameworkrisk management tiersgovernanceorganizational policy - Question #263Operating System Security
A Windows administrator wants to automate local and remote management tasks in Active Directory. Which tool is most appropriate for this?
PowerShellActive DirectoryWindows administrationautomation - Question #264Incident Handling, Risk, and Governance
Analyze the screenshot below. In what order should the vulnerabilities be remediated?
vulnerability managementrisk prioritizationremediation ordervulnerability scanning - Question #265Cloud, Web, and Application Security
What type of HTTP session tracking artifact is designed to expire once a user's web browser session is closed?
session cookiesHTTP session trackingnon-persistent cookieweb security - Question #266Networking and Core Concepts
A VPC is created with a CIDR block of 10.22.0.0/16, which of the following private subnets could be Included?
VPCCIDRsubnettingcloud networking - Question #267Access Control and Password Management
Which of the following access control principles helps prevent collusion and detect abuse of access?
separation of dutiescollusion preventionaccess controlleast privilege - Question #268Network Security
If an attacker compromised a host on a site's internal network and wanted to trick other machines into using that host as the default gateway, which type of attack would he use?
DHCP spoofingnetwork attacksdefault gateway hijackMAC flooding - Question #269Incident Handling, Risk, and Governance
Which of the following logging tasks should be evaluated in real-time?
log managementreal-time monitoringincident detectioncritical asset alerts - Question #270Linux and Cryptography
Which Linux command could a systems administrator use to determine if an attacker had opened up a new listening port on her system?
Linuxnetstatlistening portsnetwork reconnaissance detection - Question #271Incident Handling, Risk, and Governance
What is log, pre-processing?
log preprocessinglog normalizationSIEMlog format conversion - Question #272Linux and Cryptography
Which of the following tasks is the responsibility of a Linux systems administrator who is deploying hardening scripts to his systems?
Linux hardeningchange managementsecurity baselinedev environment testing - Question #273Access Control and Password Management
A web application requires multifactor authentication when a user accesses the application from a home office but does not require this when the user is in the office. What access...
adaptive authenticationMFAcontext-aware accesszero trust - Question #274Incident Handling, Risk, and Governance
Which of the following resources is a knowledge base of real-world observed adversary tactics and techniques?
MITRE ATT&CKthreat intelligenceadversary tacticsTTPs - Question #275Cloud, Web, and Application Security
Which AWS service integrates with the Amazon API Gateway to provision and renew TLS encryption needs for data in transit?
AWS Certificate ManagerTLSAPI Gatewaydata in transit - Question #276Incident Handling, Risk, and Governance
What is the purpose of notifying stakeholders prior to a scheduled vulnerability scan?
vulnerability scanningstakeholder notificationrisk managementsystem stability - Question #277Incident Handling, Risk, and Governance
Which data format is shown in the following log entry?
JSONlog formatsSIEMdata parsing - Question #278Networking and Core Concepts
Which of the following is a Personal Area Network enabled device?
PANBluetoothwireless networkingdevice types - Question #279Windows and Malware
What does PowerShell remoting use to authenticate to another host in a domain environment?
PowerShell remotingKerberosWindows authenticationdomain environment - Question #280Incident Handling, Risk, and Governance
Training an organization on possible phishing attacks would be included under which NIST Framework Core guidelines?
NIST CSFsecurity awarenessphishingProtect function - Question #281Cloud, Web, and Application Security
What Amazon Web Services (AWS) term describes a grouping of at least one datacenter with redundant power, high speed connections to other data centres and the Internet?
AWSavailability zonedatacentercloud infrastructure - Question #282Access Control and Password Management
Which Authenticates Assurance Level requires a hardware-based authenticates?
AAL3hardware authenticatorNIST 800-63MFA assurance - Question #283Networking and Core Concepts
Which field in the IPv6 header is used for QoS. or specifying the priority of the packet?
IPv6Traffic ClassQoSpacket header - Question #284Incident Handling, Risk, and Governance
What is a forensic examiner confirming when they create a cryptographic hash, such asMD5 or SHA1, of a file?
forensic hashingMD5SHA1file integrity - Question #285Network Security
What advantage would an attacker have in attacking a web server using the SSL protocol?
SSL/TLSIDS evasionencrypted trafficdowngrade attack - Question #286Linux and Cryptography
Which of the four basic transformations in the AES algorithm involves the leftward circular movement of state data?
AESShiftRowsblock ciphersymmetric encryption - Question #287Access Control and Password Management
Which of the following processes Is used to prove a user Is who they claim to be based upon something they know, have, are, and/or their physical location?
authenticationAAAidentity verificationmulti-factor - Question #288Linux and Cryptography
What method do Unix-type systems use to prevent attackers from cracking passwords using pre- computed hashes?
password hashingsaltingUnix securityrainbow tables - Question #289Networking and Core Concepts
What security advantage does the utilization of a switch as opposed to a hub offer for a secure network design?
network switchhubtraffic isolationsniffing prevention - Question #290Linux and Cryptography
An application developer would like to replace Triple DES in their software with a stronger algorithm of the same type. Which of the following should they use?
AESTriple DESsymmetric encryptionalgorithm selection - Question #291Operating System Security
Analyze the following screenshot. What conclusion can be drawn about the user account shown?
Windows user accountslocal administratorprivilege analysisscreenshot analysis - Question #292Operating System Security
Based on the iptables output below, which type of endpoint security protection has host 192.168.1.17 implemented for incoming traffic on TCP port 22 (SSH) and TCP port 23 (telnet)?
iptableshost-based firewallpacket filteringSSH security - Question #293Network Security
How does a default deny rule in a firewall prevent unknown attacks?
firewalldefault denypacket filteringnetwork access control - Question #294Incident Handling, Risk, and Governance
Which of the following is the key point to consider in the recovery phase of incident handling? Which of the following is the key point to consider in the recovery phase of inciden...
incident handlingrecovery phasesystem restorationvulnerability management - Question #295Defense in Depth and Protocols
Critical information is encrypted within an application accessible only to a small group of administrators, with a separate group of administrators holding the decryption keys. Wha...
defense in depthinformation-centricdata encryptionkey management - Question #296Network Security
An attacker is able to trick an IDS into ignoring malicious traffic through obfuscation of the packet payload. What type of IDS error has occurred?
IDSfalse negativeevasion techniquesobfuscation - Question #297Access Control and Password Management
How can an adversary utilize a stolen database of unsalted password hashes?
password hashingsaltingrainbow table attackcredential security - Question #298Cloud, Web, and Application Security
Which of the following Microsoft services integrates SSO into Microsoft 365 by syncing with on- premises servers?
Azure AD ConnectSSOMicrosoft 365identity sync - Question #299Windows and Malware
Which of the following utilities can be used to manage the Windows Firewall (WF) from the command line?
Windows FirewallnetshCLI toolsfirewall management - Question #300Incident Handling, Risk, and Governance
What is achieved with the development of a communication flow baseline?
network baselineasset identificationcommunication flowrisk management