GSLC Exam Questions
575 real GSLC exam questions with expert-verified answers and explanations. Page 8 of 12.
- Question #359Security Operations & Incident Response Leadership
Which of the following honeypots captures limited amounts of information, mainly transactional data and some limited interaction?
low-interaction honeypothoneypot typesdeception technologythreat intelligence - Question #360Security Architecture & Engineering
Which of the following is a computer file used in an operating system to map hostnames to IP addresses?
HOSTS filehostname resolutionIP mappingDNS fundamentals - Question #361Security Architecture & Engineering
Which of the following is used to describe the type of FTP access in which a user does not have permissions to list the contents of directories, but can access the contents if he k...
blind FTPFTP access typesfile transfernetwork protocols - Question #362Security Operations & Incident Response Leadership
Which system is designed to analyze, detect, and report on security-related events?
NIPSNIDSintrusion detectionsecurity monitoring - Question #363Security Operations & Incident Response Leadership
Which of the following viruses is designed to prevent antivirus researchers from examining its code by using various methods that make tracing and disassembling difficult?
armored virusmalware evasionantivirus bypassmalware analysis - Question #364Security Architecture & Engineering
Which of the following provides security by implementing authentication and encryption on Wireless LAN (WLAN)?
WEPWLAN securitywireless authenticationencryption - Question #365Security Program Management & Governance
Which of the following are the examples of administrative controls? Each correct answer represents a complete solution. Choose all that apply.
administrative controlssecurity policysecurity awareness trainingcontrol types - Question #366Security Awareness & Training
John works as a Programmer for We-are-secure Inc. On one of his routine visits to the company, he noted down the passwords of the employees while they were typing them on their com...
social engineeringshoulder surfingphysical securityinsider threat - Question #367Security Architecture & Engineering
Which of the following encryption algorithms is applied in the PGP encryption system?
PGPIDEA algorithmencryption algorithmsemail security - Question #368Security Architecture & Engineering
Rick, the Network Administrator of the Fimbry Hardware Inc., wants to design the initial test model for Internet Access. He wants to fulfill the following goals: - No external traf...
proxy serverweb filteringnetwork access controltraffic management - Question #369Security Operations & Incident Response Leadership
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008 network environment. The network is configured as a Windows Active Directory-based si...
DNS loggingaudit loggingsecurity policy implementationWindows Server - Question #370Risk Management & Compliance
Which of the following are the goals of risk management? Each correct answer represents a complete solution. Choose three.
risk management goalsrisk identificationrisk assessmentcountermeasure cost-benefit - Question #371Security Operations & Incident Response Leadership
The promiscuous mode is a configuration of a network card that makes the card pass all traffic it receives to the central processing unit rather than just packets addressed to it....
network sniffingpromiscuous modepacket capturenetwork monitoring - Question #372Security Program Management & Governance
Janet is the project manager of the NHQ Project for her company. Janet is nearly done leading the project and there have been no cost or schedule overruns in the development of the...
gold platingscope managementproject managementchange control - Question #373Security Operations & Incident Response Leadership
You are responsible for security at a company that uses a lot of Web applications. You are most concerned about flaws in those applications allowing some attacker to get into your...
web application securityvulnerability scanningpenetration testingsecurity testing methods - Question #375Security Architecture & Engineering
Which of the following protocols is used as a transport protocol for Internet dial-up connections?
PPPdial-up protocolsnetwork protocolsremote access - Question #376Security Architecture & Engineering
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Server 2008 Active Directory-based single domain single forest network. The functional level of...
asymmetric encryptionpublic key cryptographymessage confidentialityPKI - Question #377Security Awareness & Training
Which of the following programs can collect various types of personal information, such as Internet surfing habits, and Web sites that the user has visited?
spywaremalware typesdata collectionprivacy threats - Question #378Security Architecture & Engineering
Which of the following applications would be considered a data warehousing application?
data warehousingfraud detectionanalytics applicationsdata management - Question #379Security Architecture & Engineering
Which of the following options is an approach to restricting system access to authorized users?
RBACaccess control modelsauthorizationidentity management - Question #380Security Architecture & Engineering
Mark works as a Network Administrator for Infonet Inc. The company has a Windows 2000 Active Directory domain-based network. The domain contains one hundred Windows XP Professional...
WEPwireless securityMAC address filteringSSID broadcast - Question #381Security Program Management & Governance
You are the project manager for your organization and are trying to determine which vendor your organization will use. You have determined that any vendor that would like to bid on...
vendor screeningprocurement securityvendor managementselection criteria - Question #382Security Operations & Incident Response Leadership
Which of the following tools is based on Linux and used to carry out the Penetration Testing?
BackTrackpenetration testing toolsLinux security toolsethical hacking - Question #384Security Architecture & Engineering
John works as a professional Ethical Hacker. He is assigned a project to test the security of server. To accomplish this, he takes the following steps: - Instead of directly attack...
DDoS toolsbotnetdistributed attackethical hacking - Question #385Security Operations & Incident Response Leadership
John works as a professional Ethical Hacker. He has been assigned the project of testing the are-secure network. Which of the following IEEE-based traffic can be sniffed with Kisme...
wireless sniffingKismet802.11 standardsnetwork scanning - Question #386Security Program Management & Governance
Which of the following processes is NOT a part of the Project Procurement Management Knowledge Area?
project procurement managementPMBOKknowledge areasproject planning - Question #387Security Architecture & Engineering
You work in an enterprise as a Network Engineer. Your enterprise has a secure internal network. You want to apply an additional network packet filtering device that is intermediate...
DMZnetwork segmentationpacket filteringperimeter security - Question #388Security Architecture & Engineering
Which of the following are countermeasures to prevent unauthorized database access attacks? Each correct answer represents a complete solution. Choose all that apply.
database securitySQL injection preventioninput sanitizationaccess controls - Question #389Security Architecture & Engineering
Which interface does an IPS sensor use to communicate with a security appliance for management purposes?
IPS sensormanagement interfacesecurity appliancenetwork security - Question #390Security Operations & Incident Response Leadership
An attacker makes an attempt against a Web server. The result is that the attack takes the form of URLs. These URLs search for a certain string that identifies an attack against th...
IDS/IPSsignature-based detectionweb attack detectionURL pattern matching - Question #391Security Architecture & Engineering
Which of the following is used to communicate with an authentication server commonly used in UNIX networks?
TACACSauthentication protocolsUNIX networkingAAA - Question #392Security Operations & Incident Response Leadership
Which of the following backup sites takes the longest recovery time?
backup sitescold sitedisaster recoveryRTO - Question #393Security Awareness & Training
Which of the following features of IE prevent users from a type of scam that entice a user to disclose personal information such as social security number, bank account details, or...
phishing filtersocial engineeringbrowser securityuser protection - Question #394Security Architecture & Engineering
You work as a Network Administrator for NetTech Inc. You want to have secure communication on the company's intranet. You decide to use public key and private key pairs. What will...
PKIcertificate serverpublic key infrastructureasymmetric encryption - Question #395Security Awareness & Training
You have installed Windows Vista Home Premium on your home computer. The computer is connected to the Internet through an ADSL connection. You want to protect yourself from the tra...
phishing filterbrowser securityfraudulent sitesInternet Explorer - Question #396Security Operations & Incident Response Leadership
You have detected what appears to be an unauthorized wireless access point on your network. However this access point has the same MAC address as one of your real access points and...
evil twin attackrogue access pointwireless securityMAC spoofing - Question #397Risk Management & Compliance
Which of the following federal laws are related to hacking activities? Each correct answer represents a complete solution. Choose three.
computer crime lawfederal hacking statutes18 U.S.C. 1030legal compliance - Question #398Security Architecture & Engineering
You work as an Administrator for Bluesky Inc. The company has 145 Windows XP Professional client computers and eighty Windows 2003 Server computers. You want to install a security...
WTLSwireless securityWAP securityclient-server authentication - Question #399Security Operations & Incident Response Leadership
You work as a Network Administrator for Infosec Inc. The company has a Windows 2003-based server. You have installed McAfee antivirus as well as anti-spyware software on the server...
malwaresecurity software disablingFireKilleranti-security malware - Question #400Security Architecture & Engineering
John works as a professional Ethical Hacker. He has been assigned the task of testing the that the following protocols of the We-are-secure server are being used in the network: HT...
encrypted protocolsSSHSSLIPSecpacket capture - Question #401Security Operations & Incident Response Leadership
John works as a professional Ethical Hacker. He has been assigned a project to test the security local disk and obtains all the files on the Web site. Which of the following techni...
web rippingwebsite mirroringethical hacking techniquesreconnaissance - Question #402Security Program Management & Governance
Which methodology is a method to analyze the involved tasks in completing a given project, especially the time needed to complete each task, and identifying the minimum time needed...
PERTproject schedulingcritical pathproject management - Question #403Security Architecture & Engineering
Which of the following heights of fence deters only casual trespassers?
physical securityfence heightperimeter controlphysical barriers - Question #404Security Architecture & Engineering
You work as Network and Security Manager for PassGuide Inc. The management of the company is quite concerned about the security of the network. The management has assigned this tas...
mandatory access controlaccess control modelsMAC vs RBACpre-established permissions - Question #405Security Operations & Incident Response Leadership
Mark works as a Network Administrator for Perfect Inc. The company has both wired and wireless networks. An attacker attempts to keep legitimate users from accessing services that...
denial of serviceIDS/IPSnetwork attack typesthreat mitigation - Question #406Security Architecture & Engineering
John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the c...
steganographydata exfiltrationinsider threatcovert channels - Question #407Security Architecture & Engineering
Which of the following protocols does IPsec use to perform various security functions in the network? Each correct answer represents a complete solution. Choose all that apply.
IPsecIKEESPAuthentication Header - Question #408Risk Management & Compliance
You are the project manager of a Web development project. You want to get information about your competitors by hacking into their computers. You and the project team determine sho...
risk transferencerisk response strategiesthird-party riskproject risk management - Question #409Security Operations & Incident Response Leadership
Maria works as a professional Ethical Hacker. She has been assigned the project of testing the Inc. In which of the following steps of malicious hacking does dumpster diving come u...
reconnaissancedumpster divingethical hacking phasesinformation gathering - Question #410Security Program Management & Governance
What is the term used to describe the cost of the solution after the solution has been implemented in production by a vendor?
total cost of ownershipTCOvendor managementcost analysis