GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 7 of 9.
- Question #301Windows and Malware
Dilbert wants to have a script run on his Windows server every time Wally logs into it. Where should he place this script?
Group Policylogon scriptsuser configurationWindows Server - Question #302Linux and Cryptography
Which file would the entry below be found in? net.ipv6.conf.all.acctpt-ra=0
sysctlLinux configurationIPv6kernel parameters - Question #303Linux and Cryptography
What could be used to mitigate hash collisions?
hash collisioncryptographic strengthbit lengthalgorithm design - Question #304Operating System Security
When file integrity checking is enabled, what feature is used to determine if a monitored file has been modified?
file integrity monitoringone-way hashHIDSchange detection - Question #305Cloud, Web, and Application Security
A program has allocated 10 characters of space for user's response on a form. The application does not validate the number of characters that a user can input into the field before...
buffer overflowinput validationapplication vulnerabilitymemory security - Question #306Network Security
A security analyst has entered the following rule to detect malicious web traffic: alert tcp any -> 192.168.1.0/24 SO (msg: Attempted SQL Injection!"; sld:20000001;) How can this r...
Snort rulesIDS tuningfalse positivesrule specificity - Question #307Networking and Core Concepts
What must be added to VLANs to improve security?
VLANaccess control listsnetwork segmentationnetwork security - Question #308Linux and Cryptography
Which services will have listening ports on a hardened Linux log server?
Linux hardeningsyslogSSHattack surface reduction - Question #309Networking and Core Concepts
What is it called when an OSI layer adds a new header to a packet?
OSI modelencapsulationpacket headersnetworking fundamentals - Question #310Defense in Depth and Protocols
A database is accessed through an application that users must authenticate with, on a host that only accepts connections from a subnet where the business unit that uses the data is...
defense in depthnetwork segmentationlayered securityprotected enclaves - Question #311Operating System Security
What is a characteristic of iOS security?
iOS securitymobile securityplatform securitysecurity architecture - Question #312Incident Handling, Risk, and Governance
Which of the following activities would take place during the containment phase?
incident containmentlog correlationPCAP analysisforensic investigation - Question #313Cloud, Web, and Application Security
What is a recommended defense against SQL injection, OS injection, and buffer overflows?
SQL injectioninput validationbuffer overflowOS injection - Question #314Network Security
What advantage does a Client-to-Client VPN have over other types of VPNs?
VPNclient-to-client VPNend-to-end encryptionnetwork traffic - Question #315Defense in Depth and Protocols
An organization keeps its intellectual property in a database. Protection of the data is assigned to one system administrator who marks the data, and monitors for this intellectual...
defense in depthinformation centricdata classificationDLP - Question #316Linux and Cryptography
If a Linux administrator wanted to quickly filter out extraneous data and find a running process named RootKit, which command could he use?
Linux commandsps commandprocess managementgrep - Question #317Access Control and Password Management
Rainbow Tables are used in what kind of password cracking?
rainbow tablespassword crackingpre-computationhash - Question #318Linux and Cryptography
A simple cryptosystem that keeps the same letters and shuffles the order is an example of what?
permutation ciphertranspositionclassical cryptographycryptosystem - Question #319Defense in Depth and Protocols
A company disables cd drives for users; what defense strategy is this a part of?
defense in depthprotected enclavesremovable mediaaccess restriction - Question #320Cloud, Web, and Application Security
What dots Office 365 use natively for authentication?
Office 365Azure Active Directorycloud authenticationExchange Online - Question #321Defense in Depth and Protocols
An email system administrator deploys a configuration blocking all inbound and outbound executable files due to security concerns. What Defense in Depth approach is being used?
defense in depthvector orientedemail securityexecutable filtering - Question #322Access Control and Password Management
In the AGULP model, who should be assigned permissions and privileges?
AGULP modelActive Directorygroup permissionsaccess control - Question #323Network Security
Which of the following correctly describes a stateless packet filter?
stateless packet filterfirewallpacket filteringnetwork security - Question #324Windows and Malware
In an Active Directory domain, which is the preferred method of keeping host computers patched?
WSUSpatch managementActive DirectoryWindows Server - Question #325Networking and Core Concepts
What is the purpose of a TTL value?
TTLpacket routingIP protocolhop count - Question #326Incident Handling, Risk, and Governance
What security practice is described by NIST as the application of science to the identification, collection, examination, and analysis of data while maintaining data integrity and...
digital forensicsNISTchain of custodydata integrity - Question #327Networking and Core Concepts
The TTL can be found in which protocol header?
TTLIP headerprotocol headersTCP/IP - Question #328Access Control and Password Management
Which of the following consists of the security identifier number (SID) of your user account, the SID of all of your groups and a list of all your user rights?
Security Access TokenSIDWindows securityaccess control - Question #329Linux and Cryptography
Analyze the file below. When will the program /home/sink/utils/remove temp hies.py run?
crontabLinux schedulingcron jobstask automation - Question #330Operating System Security
What technique makes it difficult for attackers to predict the memory address space location for code execution?
memory protectionASLRexploit mitigationbuffer overflow - Question #331Cloud, Web, and Application Security
A system administrator sees the following URL in the webserver logs: Which action will mitigate against this attack?
web attackinput filteringinjection attackURL manipulation - Question #332Windows and Malware
What is the fundamental problem with managing computers in stand-alone Windows workgroups?
Windows workgroupSecurity Access Tokenlocal authenticationdomain security - Question #333Access Control and Password Management
Jonny Is an IT Project Manager. He cannot access the folder called "IT Projects" but can access a folder called "Sales Data" even though he's not on the sales team. Which informati...
authorizationleast privilegeaccess controlinformation security principles - Question #334Linux and Cryptography
What cryptographic technique does file Integrity monitoring employ?
file integrity monitoringone-way hasheshashingcryptography - Question #335Network Security
Which of the following is a potential WPA3 security issue?
WPA3wireless securitybackward compatibilityWi-Fi security - Question #336Linux and Cryptography
Which asymmetric algorithm is used only for key exchange?
Diffie-Hellmanasymmetric cryptographykey exchangecryptographic algorithms - Question #337Cloud, Web, and Application Security
Which of the following is Azure's version of a superuser?
AzureGlobal Administratorcloud IAMprivileged roles - Question #338Windows and Malware
Which of the following is an example of a BitLocker recovery password?
BitLockerrecovery passworddisk encryptionWindows encryption - Question #339Cloud, Web, and Application Security
Which of the following attacks can be mitigated by avoiding making system calls from within a web application?
OS command injectionSQL injectionweb application securityinput validation - Question #340Networking and Core Concepts
Use Wireshark to analyze Desktop;PCAP FILES/charile.pcap What is the destination IP address in packet #3?
Wiresharkpacket analysisPCAPnetwork forensics - Question #341Network Security
Use nmap to discover a host on the 10.10.10.0/24 network, scanning only port 8082 and using the SYN or Stealth scan approach. Which host has a service called -blackice-alerts"?
nmapSYN scanport scanningnetwork reconnaissance - Question #342Linux and Cryptography
Use Hashcat to crack a local shadow file. What Is the password for the user account AGainsboro? - The shadow file (shadow) and Hashcat wordlist (gsecwordlist.txt) are located in th...
Hashcatpassword crackingMD5shadow file - Question #343Linux and Cryptography
Use Hashcat to crack a local shadow file. What Is the password for the user account AGainsboro? - The shadow file (shadow) and Hashcat wordlist (gsecwordlist.txt) are located in th...
Hashcatpassword crackingMD5shadow file - Question #344Networking and Core Concepts
Open the MATE terminal and use the tcpdump program to read - /pcaps /cass tech.pcap. What is the source port number?
tcpdumppacket analysisPCAPnetwork traffic - Question #345Linux and Cryptography
What is the SHA1 hash of the Ale /bin/Is?
SHA1file hashingLinuxfile integrity - Question #346Windows and Malware
Use PowerShell ISE to examineC:\Windows\security\templates\WorkstationSecureTemplate.inf. Which setting is configured in the template?
PowerShellsecurity templatesWindows securityaccount lockout - Question #347Defense in Depth and Protocols
In the directory C:\lmages\steer there Is an Image file lmage_4240.png with a data string encoded inside the file. What word is hidden in the file?
steganographydata hidingimage analysisforensics - Question #348Windows and Malware
Launch Calculator (calc.exe). Using PowerShell, retrieve the Calculator Process Information. What is the value of the File Version property? Hint: The process name of Calculator is...
PowerShellprocess informationWindows administrationfile version - Question #349Windows and Malware
Using PowerShell ISE running as an Administrator, navigate to the C:\hlindows\security\tevplatesdirectory. Use secedit.exe in analyze mode to compare the temp.sdb and uorkstdtionSe...
seceditsecurity templatesPowerShelluser rights analysis - Question #350Network Security
Use sudo to launch Snort with the, /etc /snort /snort.conf file In full mode to generate alerts based on incoming traffic to echo. What is the source IP address of the traffic trig...
SnortIDSintrusion detectionnetwork alerts