GSEC Exam Questions
409 real GSEC exam questions with expert-verified answers and explanations. Page 8 of 9.
- Question #352Defense in Depth and Protocols
Which of the following statements regarding Secure Sockets Layer (SSL) are true? Each correct answer represents a complete solution. Choose all that apply.
SSLTLSencryptionmessage integrity - Question #353Networking and Core Concepts
Which of the following protocols multicasts messages and information among all member devices in an IP multicast group?
IGMPIP multicastnetwork protocolsmulticast groups - Question #354Linux and Cryptography
Which of the following is not an encryption technology?
encryption algorithmsBlowfish3DESMD5 - Question #355Incident Handling, Risk, and Governance
Which of the following statements about the availability concept of Information security management is true?
CIA triadavailabilityinformation security managementsecurity concepts - Question #356Networking and Core Concepts
You work as a Network Administrator for Perfect World Inc. You are configuring a network that will include 1000BaseT network interface cards in servers and client computers. What i...
1000BaseTGigabit Ethernetsegment lengthcable standards - Question #357Access Control and Password Management
The /cat/etc/passwd file on a client computer contains the following entry: Martha:x:::::bin/false Which of the following is true for Martha?
/etc/passwdLinux authenticationshell assignmentuser access control - Question #358Incident Handling, Risk, and Governance
Which of the following terms is synonymous with the willful destruction of another person's property?
vandalismsecurity terminologycybercrimeproperty destruction - Question #359Network Security
Which of the following are advantages of Network Intrusion Detection Systems (NIDS)? (A) Analysis of encrypted traffic (B) Provide insight into network traffic (C) Detection of net...
NIDSintrusion detectionnetwork monitoringsecurity tools - Question #360Networking and Core Concepts
Which of the following protocols is used by a host that knows its own MAC (Media Access Control) address to query a server for its own IP address?
RARPMAC addressIP addressingaddress resolution - Question #361Network Security
What is the motivation behind SYN/FIN scanning?
SYN/FIN scanport scanningdenial of servicenetwork attacks - Question #362Networking and Core Concepts
There is not universal agreement on the names of the layers in the TCP/IP networking model. Which of the following is one of the functions of the bottom layer which is sometimes ca...
TCP/IP modellink layernetwork access layerEthernet - Question #363Networking and Core Concepts
Which of the following is a private, RFC 1918 compliant IP address that would be assigned to a DHCP scope on a private LAN?
RFC 1918private IP addressesDHCPnetwork addressing - Question #364Linux and Cryptography
When using Pretty Good Privacy (PGP) to digitally sign a message, the signature is created in a two- step process. First, the message to be signed is submitted to PGP's cryptograph...
PGPdigital signaturesSHA-1cryptographic hash - Question #365Incident Handling, Risk, and Governance
You are the security director for an off-shore banking site. From a business perspective, what is a major factor to consider before running your new vulnerability scanner against t...
vulnerability scanningfalse positivessecurity assessmentrisk management - Question #366Operating System Security
Which of the following is a benefit to utilizing Cygwin for Windows?
CygwinWindowsLinux environmentcross-platform tools - Question #367Defense in Depth and Protocols
What technical control provides the most critical layer of defense if an intruder is able to bypass all physical security controls and obtain tapes containing critical data?
encryptiondata protectionphysical securitydefense in depth - Question #368Networking and Core Concepts
Two clients connecting from the same public IP address (for example - behind the same NAT firewall) can connect simultaneously to the same web server on the Internet, provided what...
NATsource portsTCP connectionsport addressing - Question #369Network Security
Which of the following is used to implement a procedure to control inbound and outbound traffic on a network?
ACLaccess control liststraffic filteringnetwork security - Question #370Linux and Cryptography
John works as a Network Administrator for Perfect Solutions Inc. The company has a Linux- based network. John is working as a root user on the Linux operating system. He executes t...
Linuxroot userUIDshell environment variables - Question #371Linux and Cryptography
Which of the following is a security threat if included in the search path of a computer?
PATH variableLinux securitycurrent directoryprivilege escalation - Question #372Linux and Cryptography
Which of the following directories contains the log files in Linux?
Linux/var/loglog filessystem directories - Question #373Networking and Core Concepts
Which of the following statements are true about satellite broadband Internet access? Each correct answer represents a complete solution. Choose two.
satellite broadbandlatencyinternet accessbroadband costs - Question #374Linux and Cryptography
You want to temporarily change your primary group to another group of which you are a member. In this process, a new shell will be created, and when you exit the shell, your previo...
newgrpLinux groupsprimary groupshell commands - Question #375Windows and Malware
Rick works as a Network Administrator. He is configuring the systems for maximum security. Before using the security template, he wants to edit it to change some of the security se...
security templatesMMC snap-inWindows securityGroup Policy - Question #376Incident Handling, Risk, and Governance
Which of the following enables an inventor to legally enforce his right to exclude others from using his invention?
patentintellectual propertylegal rightsgovernance - Question #377Networking and Core Concepts
Which of the following ports is the default port for IMAP4 protocol?
IMAP4TCP port 143email protocolsport numbers - Question #378Linux and Cryptography
Which of the following is a standard Unix command that would most likely be used to copy raw file system data for later forensic analysis?
dd commandforensic imagingraw file systemLinux tools - Question #379Windows and Malware
Which of the following is NOT a recommended best practice for securing Terminal Services and Remote Desktop?
Terminal ServicesRemote DesktopRDPfirewall rules - Question #380Cloud, Web, and Application Security
When an IIS filename extension is mapped, what does this mean?
IISfilename extension mappingweb serverscript interpreter - Question #381Linux and Cryptography
Which Linux file lists every process that starts at boot time?
inittabboot processLinux startupinit - Question #382Networking and Core Concepts
When trace route fails to get a timely response for a packet after three tries, which action will it take?
tracerouteTTLnetwork diagnosticsICMP - Question #383Networking and Core Concepts
You are examining an IP packet with a header of 40 bytes in length and the value at byte 0 of the packet header is 6. Which of the following describes this packet?
IPv6packet header analysisIP version fieldprotocol identification - Question #384Access Control and Password Management
Which of the following is a valid password for a system with the default "Password must meet complexity requirements" setting enabled as part of the GPO Password policy requirement...
password complexityGPO password policyWindows authenticationcomplexity requirements - Question #385Incident Handling, Risk, and Governance
At what point in the Incident Handling process should an organization determine its approach to notifying law enforcement?
incident handlinglaw enforcement notificationincident responsepreparation phase - Question #386Network Security
Which of the following is TRUE regarding the ability of attackers to eavesdrop on wireless communications?
wireless eavesdroppingRF signal rangepassive attackwireless security - Question #387Linux and Cryptography
An employee is currently logged into the corporate web server, without permission. You log into the web server as 'admin" and look for the employee's username: "dmaul" using the "w...
bash historylog tamperingLinux forensicsintrusion indicators - Question #388Network Security
What type of attack can be performed against a wireless network using the tool Kismet?
Kismetwireless eavesdroppingwireless scanning toolspassive monitoring - Question #389Linux and Cryptography
Which of the following is an Implementation of PKI?
PKISSLpublic key infrastructurecryptography implementations - Question #390Incident Handling, Risk, and Governance
Which of the following statements about policy is FALSE?
security policypolicy writinggovernancewhat vs how - Question #391Linux and Cryptography
You work as a Network Administrator for Tech Perfect Inc. The company has a Linux-based network. You have configured a VPN server for remote users to connect to the company's netwo...
VPN3DESLinux encryptionremote access - Question #392Linux and Cryptography
You work as a Linux Technician for Tech Perfect Inc. You want to protect your server from intruders who exploit services that are started with TCP Wrappers. Which of the following...
TCP Wrappershosts.denyhosts.allowLinux access control - Question #393Operating System Security
Which of the following statements about service pack are true? Each correct answer represents a complete solution. Choose two.
service packspatch managementsoftware updatesOS maintenance - Question #394Networking and Core Concepts
Which of the following tools is similar to the ping tool but operates at OSI data link layer using the address resolution protocol?
ARPOSI data link layernetwork diagnosticsping utility - Question #395Networking and Core Concepts
Which of the following is the default port for Simple Network Management Protocol (SNMP)?
SNMPUDP port 161network managementport numbers - Question #396Linux and Cryptography
Which of the following are the ways of sending secure e-mail messages over the Internet? Each correct answer represents a complete solution. Choose two.
S/MIMEPGPemail encryptionsecure messaging - Question #397Linux and Cryptography
After enabling shadowed passwords in a Linux server, where does Linux keep the passwords?
shadow passwords/etc/shadowLinux authenticationpassword storage - Question #398Network Security
Which of the following processes is used by remote users to make a secure connection to internal resources after establishing an Internet connection?
VPN tunnelingremote accesssecure connectionnetwork security - Question #399Linux and Cryptography
You work as a Network Administrator for Net World Inc. The company has a Linux-based network. You have downloaded an application from the Internet. Before starting the installation...
sum commandfile integritychecksumLinux tools - Question #400Windows and Malware
You have reason to believe someone with a domain user account has been accessing and modifying sensitive spreadsheets on one of your application servers. You decide to enable audit...
file auditingAudit Object AccessGroup PolicyWindows audit logs - Question #401Operating System Security
Which of the following BEST describes the two job functions of Microsoft Baseline Security Analyzer (MBSA)?
MBSAvulnerability scannersecurity patchingWindows security baseline