GSLC Exam Questions
575 real GSLC exam questions with expert-verified answers and explanations. Page 9 of 12.
- Question #411Security Architecture & Engineering
Which of the following are the countermeasures against WEP cracking? Each correct answer represents a part of the solution. Choose all that apply.
WEP securitywireless encryptionWEP cracking countermeasureskey management - Question #412Security Architecture & Engineering
Which of the following types of cryptography algorithms is a symmetric key cipher which operates on fixed-length groups of bits, termed blocks, with an unvarying transformation?
block ciphersymmetric encryptioncryptography algorithmsfixed-length blocks - Question #413Security Architecture & Engineering
Which of the following tools is an automated tool that is used to implement SQL injections and to retrieve data from Web server databases?
SQL injectionautomated attack toolsweb application securityAbsinthe - Question #414Risk Management & Compliance
You and your project team are just starting the risk identification activities for a project that is scheduled to last for 18 months. Your project team has already identified a lon...
risk identificationiterative risk processrisk management lifecycleproject risk - Question #415Security Program Management & Governance
Which of the following terms describes the statement given below? "It refers to a range of skills, tools, and techniques used to manage time when accomplishing specific tasks, proj...
time managementprogram managementplanning and prioritizationresource management - Question #416Security Architecture & Engineering
Which of the following domains of the DNS hierarchy consists of categories found at the end of domain names, such as .com or .uk and divides the domains into organizations (.org),...
DNS hierarchytop-level domaindomain namingDNS structure - Question #419Security Operations & Incident Response Leadership
You are taking over the security of an existing network. You discover a machine that is not being used as such, but has software on it that emulates the activity of a sensitive dat...
honeypotdeception technologyintrusion detectionnetwork defense - Question #420Security Architecture & Engineering
You are a Network Administrator in an enterprise. You have been assigned the task of installing Windows 2000 and some other applications, on each computer on the network. But in th...
automated deploymentWindows Server administrationOS installationenterprise infrastructure - Question #421Security Architecture & Engineering
Which of the following statements are true about MS-CHAPv2? Each correct answer represents a complete solution. Choose all that apply.
MS-CHAPv2authentication protocolsPPTPEAP-TLS - Question #422Metrics, Reporting & Future State
You are the program manager for your organization. You have proposed a program that will cost $750,000 and will last for four years. Management is concerned with the cost of the pr...
ROI calculationprogram investmentfuture valuefinancial justification - Question #423Security Operations & Incident Response Leadership
John works as a professional Ethical Hacker. He is assigned a project to test the security of Which of the following statements are true about rootkits? Each correct answer represe...
rootkitsbackdoorsmalware capabilitiesprivilege escalation - Question #424Security Architecture & Engineering
You are responsible for security at a company that specializes in e-commerce. You realize that given the high volume of Web traffic, there is a significant chance of someone being...
honeypotintrusion deceptionperimeter defensee-commerce security - Question #425Security Architecture & Engineering
You are implementing wireless access at a defense contractor. Specifications say, you must implement the AES Encryption algorithm. Which encryption standard should you choose?
WPA2AES encryptionwireless security802.11 - Question #426Security Architecture & Engineering
Which of the following password authentication schemes enables a user with a domain account to log on to a network once, using a password or smart card, and to gain access to multi...
Single Sign-Onauthenticationdomain accountsKerberos - Question #427Security Architecture & Engineering
Which of the following RAID levels will you use to implement a RAID system for providing fault tolerance to a database?
RAID levelsfault tolerancedata redundancydatabase availability - Question #428Security Architecture & Engineering
Which of the following items are generally analyzed by Internet filters? Each correct answer represents a complete solution. Choose three.
content filteringURL filteringcertificate inspectionweb filtering - Question #429Security Architecture & Engineering
What does a firewall check to prevent certain ports and applications from getting the packets into an Enterprise?
firewallpacket inspectionport filteringOSI layers - Question #430Security Architecture & Engineering
Victor wants to send an encrypted message to his friend. He is using certain steganography technique to accomplish this task. He takes a cover object and changes it accordingly to...
steganographydistortion techniquedata hidingcover object - Question #431Security Architecture & Engineering
Which of the following tools monitors the radio spectrum for the presence of unauthorized, rogue access points and the use of wireless attack tools?
WIPSwireless intrusion preventionrogue access pointswireless monitoring - Question #432Security Operations & Incident Response Leadership
Which of the following is the practice of a domain name registrant using the five-day "grace period" (the Add Grace Period or AGP) at the beginning of the registration of an ICANN-...
domain tastingICANNDNS abuseAdd Grace Period - Question #433Security Program Management & Governance
You are the program manager for your organization. Management has asked that you determine when resources, such as leased equipment, are no longer needed so that you may release th...
resource controlprogram managementleased equipmentresource release - Question #434Security Architecture & Engineering
IDS systems can be classified in many different ways. Which of the following is not a way that IDS systems are commonly classified?
IDS classificationnetwork-based IDShost-based IDSactive vs passive IDS - Question #435Security Architecture & Engineering
Which of the following provides the best protection against a man-in-the-middle attack?
man-in-the-middle attackencryptionattack mitigationnetwork security controls - Question #436Security Architecture & Engineering
You are concerned about war driving bringing hackers attention to your wireless network. What is the most basic step you can take to mitigate this risk?
SSID broadcastwar drivingwireless securitynetwork visibility - Question #437Security Program Management & Governance
You have been asked to create a project charter for a new database project. Management has stressed that in order to effectively create a project charter, you'll first need to unde...
project charterproject managementproject objectivesmilestone planning - Question #438Security Architecture & Engineering
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Server 2008 network environment. The network is configured as a Windows Active Directory-based s...
802.1Xwireless authenticationenterprise wireless securitygroup policy - Question #439Security Architecture & Engineering
Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
confidentialitycryptographic servicesCIA triadinformation disclosure - Question #440Security Architecture & Engineering
Which of the following relies on a physical characteristic of the user to verify his identity?
biometricsauthentication factorsidentity verificationphysical characteristics - Question #441Security Awareness & Training
Which of the following types of attacks entices a user to disclose personal information such as social security number, bank account details, or credit card number?
phishingsocial engineeringpersonal informationcredential theft - Question #442Security Architecture & Engineering
Which of the following are considered Bluetooth security violations? Each correct answer represents a complete solution. Choose two.
Bluetooth securityBluesnarfingBluebug attackwireless attacks - Question #443Security Architecture & Engineering
Rick works as a Computer Forensic Investigator for BlueWells Inc. He has been informed that some confidential information is being leaked out by an employee of the company. Rick su...
steganographylinguistic steganographytext semagramsdata concealment - Question #444Security Architecture & Engineering
Which of the following can provide security against man-in-the-middle attack?
man-in-the-middle attackdata encryptionnetwork securityencryption in transit - Question #445Metrics, Reporting & Future State
Consider the following diagram: What is the highlighted area of the diagram known as?
Rule of Sevencontrol chartsstatistical process controlquality metrics - Question #446Security Operations & Incident Response Leadership
You are an Administrator for a network at an investment bank. You are concerned about individuals breeching your network and being able to steal data before you can detect their pr...
honeypotintrusion detectionnetwork securitythreat detection - Question #447Security Architecture & Engineering
John works as a professional Ethical Hacker. He has been assigned the project of testing the to a man-inthe-middle attack since the key exchange process of the cryptographic algori...
Diffie-Hellmankey exchangeman-in-the-middlecryptographic algorithms - Question #448Security Operations & Incident Response Leadership
What are the steps related to the vulnerability management program? Each correct answer represents a complete solution. Choose all that apply.
vulnerability managementsecurity baselinepolicy definitionsecurity monitoring - Question #449Security Architecture & Engineering
One of the sales people in your company complains that sometimes he gets a lot of unsolicited messages on his PDA. After asking a few questions, you determine that the issue only o...
BluejackingBluetooth securitywireless attacksmobile security - Question #450Security Architecture & Engineering
You want to use PGP files for steganography. Which of the following tools will you use to accomplish the task?
steganographyPGPStealth tooldata hiding - Question #451Risk Management & Compliance
John works as a Website Administrator in ABC Inc. The company has to set a privacy policy on all the computers. The policy requires John to restrict only third party cookies that d...
cookie policybrowser privacythird-party cookiesprivacy settings - Question #452Security Architecture & Engineering
You are advising a school district on disaster recovery plans. In case a disaster affects the main IT centers for the district they will need to be able to work from an alternate l...
disaster recoverycold sitebusiness continuityrecovery site selection - Question #453Security Operations & Incident Response Leadership
You work as a professional Ethical Hacker. You are assigned a project to test the security of suspect that your friend has installed the keyghost keylogger onto your computer. Whic...
keyloggeranti-keyloggerendpoint securitycountermeasures - Question #454Security Architecture & Engineering
Which of the following statements about IPSec are true? Each correct answer represents a complete solution. Choose two.
IPSecAuthentication HeaderEncapsulating Security Payloadnetwork security protocols - Question #456Risk Management & Compliance
You work as a project manager for TYU project. You are planning for risk mitigation. You need to identify the risks that will need a more in-depth analysis. Which of the following...
qualitative risk analysisrisk identificationrisk prioritizationrisk management - Question #457Security Architecture & Engineering
You work as a Network Administrator for Tech Perfect Inc. The company has a Linux-based network. You have configured a VPN server for remote users to connect to the company's netwo...
VPN3DES encryptionLinux networkingremote access security - Question #458Security Operations & Incident Response Leadership
You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extension of your enterprise. The networking, to be done in the new extension, requires differen...
incident handlingpreparation phaseincident managementnetwork policy - Question #459Security Operations & Incident Response Leadership
You work as an Incident handling manager for Orangesect Inc. You detect a virus attack incident in the network of your company. You develop a signature based on the characteristics...
incident handlingeradication phasevirus signaturemalware response - Question #460Security Architecture & Engineering
Mark works as a Network Administrator for Infonet Inc. The company has a Windows 2003 domainbased network. The network contains five Windows 2003 member servers and 300 Windows XP...
PEAP802.1x authenticationwireless securityEAP protocols - Question #461Risk Management & Compliance
You are the project manager for the TTR project. You are in the process of gathering information for risk identification. You ask experts to participate in the process through thei...
Delphi techniquerisk identificationexpert judgmentanonymous survey - Question #462Security Program Management & Governance
Which of the following activities result in change requests? Each correct answer represents a complete solution. Choose all that apply.
change requestscorrective actionsdefect repairpreventive actions - Question #463Security Program Management & Governance
Which of the following contract types is described in the statement below? "This contract type provides no incentive for the contractor to control costs and hence is rarely utilize...
contract typescost plus percentage of costprocurementcontractor incentives