Browse all practice questions for the GIAC Security Essentials Certification (GSEC) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GSEC Practice Test 2026 – Complete Exam Preparation course image
All questions

These questions are part of the practice quiz. Start practicing

  • What type of backup retains all data regardless of previous backups?
  • Vulnerability scanners do NOT do which of the following?
  • What functionality does TripWire provide in terms of security?
  • H.245 is used for what aspects of an H.323 session?
  • Which method can improve the security of a WiFi network?
  • Which of the following is not a benefit of VoIP?
  • A substitution steganography uses this part of a carrier file.
  • If you observe many ARP responses without matching ARP requests, what are you likely witnessing?
  • If your vulnerability scan shows your Web server is vulnerable, but you are running version 2.6 of that software, what might be the reason?
  • What is a common use case for virtualizing servers?
  • Which file contains mappings between ports and the names of applications associated with them?
  • How can you enhance a group’s security permissions in Active Directory?
  • Which term describes software that is designed to exploit vulnerabilities in computers or networks?
  • What is the main purpose of using a hashing algorithm in password storage?
  • What does PAM do to protect password security?
  • Skype uses what type of communication to connect its users?
  • What technology is often used to enhance security in virtual environments?
  • Which VMWare product is available for free to run virtual machines?
  • What is the primary difference between a virus and a worm?
  • What is the primary use of a spike strip in security?
  • What is the primary function of a firewall?
  • What is the purpose of the 'htop' utility?
  • What is a common use of Group Policy in a Windows environment?
  • Why might a UDP scan take longer to complete than other types of scans?
  • Which of the following is NOT a reason for packing a program?
  • Which of the following tactics might allow a perpetrator to gain a lot of information from a device?
  • What does the SSID stand for in a wireless network context?
  • Without virtual memory, what were programmers typically required to use?
  • What is a translation lookaside buffer used for?
  • Your boss wants to fix a critical vulnerability on the database server immediately. What should you do?
  • What are two primary responsibilities of the hypervisor?
  • What is the best way to protect data at rest?
  • In response to SQL injection errors detected in a commercial web application, which action would NOT be a part of remediation?
  • The frequent appearance of popup ads while browsing the web is an indication of what type of malware?
  • What can be a major downside of using compression in an intrusion detection system?
  • What tool would you use to enable auditing on systems in your network?
  • How are security policies best described?
  • Which command would you use to view the current running processes?
  • When creating a vulnerability scanning schedule for a large network, what is an effective strategy?
  • Which of these would be considered the most important part of cryptography?
  • Which action is likely to help prevent infections from viruses?
  • To determine whether a project makes financial sense, you would perform which of these?
  • Which type of authentication does SIP use?
  • Which of the following will help protect a Web application infrastructure from Web attacks like SQL Injection?
  • Which utility makes use of ICMP to function?
  • Which utility would you use to monitor CPU usage of individual processes updated every three seconds?
  • What is the subnet mask for the address block 10.1.0.0 with a /24 prefix?
  • What is the principle of least privilege implemented in?
  • A session border controller can help with which of the following security situations?
  • What type of attack is typically characterized by overwhelming a system with traffic to disrupt services?
  • Backups and replication are two strategies primarily used for what purpose?
  • According to the syslog configuration, where are login messages stored?
  • What key combination generates a SIGINT signal in a terminal?
  • What's the difference between virtualization and emulation?
  • SQL Injection attacks are targeted at what?
  • Which of the following can be used to authenticate someone?
  • Public key algorithms are also called what?
  • What does Microsoft recommend for assigning permissions to a set of users?
  • What can you infer if all results of a port scan show filtered ports?
  • In order to validate a certificate presented to you, what would you need?
  • For which of the following scenarios would a deterrent control be most appropriate?
  • WEP was superseded by WPA because of what problem?
  • In which scenario is ARP spoofing most likely occurring?
  • If the SLE for a system is $5,000 and the ARO is 2, what is the ALE?
  • Which command is used to set file permissions in Linux?
  • Which form of attack is specifically designed to exploit weaknesses in Bluetooth?
  • If vulnerability scans are routinely run but no one is reviewing the reports, what can be said about those scans?
  • What is a key advantage of a boot sector virus?
  • What effect does the iptables rule 'iptables -A INPUT -j DROP' have on network traffic?
  • Which of these is a common method to enhance physical security in sensitive areas?
  • Which of the following is an example of a passive security measure?
  • Which technology allows you to block network access based on the application being used to initiate the request?
  • In what format are Windows Firewall logs stored?
  • Authentication is the process of doing what?
  • What are significant challenges for intrusion detection systems?
  • What do intrusion detection systems NOT need in order to operate effectively?
  • PGP uses what sort of system to verify the identity of the certificate holder?
  • If you observe unusual network traffic originating from your computer to foreign IPs, what could this suggest?
  • What class is the address 170.19.82.45?
  • Which security principle emphasizes the need to limit user access rights to the bare minimum?
  • What concept ensures that only the necessary privileges are granted to users?
  • If you wanted to generate keys in a secure fashion to exchange encrypted information, which process would you use?
  • What might be a sign that malware is present on a system?
  • What should your first action be before conducting an unscheduled vulnerability scan?
  • What does a vulnerability scan that identifies a firewall indicate?
  • What is the primary benefit of using WPA over WEP?
  • What does an organization need to ensure both complete operations recovery and continued operations?
  • What is the primary goal of an incident response plan?
  • If recyclables ignite due to high temperatures, what class of fire would this represent?
  • What can you say about the following packet capture: 14:18:25.906002 apollo.it.luc.edu.1000 > x-terminal.shell: S...?
  • Which of the following practices is crucial for maintaining data integrity during data storage?
  • Which of the following best defines a Denial of Service (DoS) attack?
  • A very primitive but popular type of encryption cipher is called what?
  • If your IDS alerts you about a packet with the same source and destination, what could this indicate?
  • In the context of cybersecurity, what does the term "threat landscape" refer to?
  • What are Duqu and Stuxnet examples of?
  • What is the main function of a firewall?
  • To conduct static analysis on a piece of malware, what is a possible action?
  • Your intrusion detection system has alerted you that you are getting a SIP attack. What would you consider this attack to be, based solely on the information you have?
  • Where would you find statistics on the inet process with process ID 1 in your filesystem?
  • Your bank is implementing a token-based solution for authentication. What type of authentication will they be using?
  • Embedded wires in glass are designed to achieve which of the following?
  • The SUBSCRIBE message can be used for what purpose?
  • What can John the Ripper be used for?
  • Network devices and dialup users may be authenticated using which of the following protocols?
  • With the following IP header, what is the destination IP address: 45 00 03 3D 1E EB 40 00 40 06 5D E8 C0 A8 01 16 AD C2 4B 67?
  • Which command would you use in a batch file to make changes to the Windows registry?
  • What is the order of messages in a three-way handshake?
  • What component does water primarily remove to extinguish a fire?
  • What is the most important criterion when deploying an intrusion prevention system on your network?
  • How would you define the host operating system?
  • In the address ab00:fc87:234a:0090:5120:ffab:bc8a:0098/23, what does the /23 indicate?
  • Which of the following best describes spyware?
  • Which of the following is a private address (RFC1918)?
  • Your firewall has a rule blocking inbound ICMP messages unless they are responses to a request originated from inside the network. Which attack is most likely being protected against?
  • What type of lock would be appropriate for securing a facility during unoccupied hours?
  • What type of engineering is utilized by malware?
  • What can you accomplish by hiding your SSID?
  • What was SIP developed for?
  • What security solution would you implement to prevent employees from browsing Facebook during work hours?
  • What is a common way in which ransomware operates?
  • What is the primary function of an intrusion detection system?
  • If you see the IP address fe80::0050:8790:4554:2300/16, what does the :: indicate?
  • What is the benefit of using snapshots in virtualization?
  • Which decade saw the creation of the first virtual machines?
  • The challenge of trying to find a collision in a hashing algorithm is called what?
  • Which method is ineffective in breaking the security of a physical barrier?
  • How many bits are in the NETWORK portion of the following address block: Address: 10.1.0.0, Subnet: 255.255.255.224?
  • Adding an additional alphanumeric character to the required length of a password will multiply the potential passwords by how many?
  • What is a common characteristic of adware?
  • How should you prioritize the list of vulnerabilities from a Nexpose scan?
  • Which security measure is designed to protect a network by blocking unauthorized access while permitting outward communication?
  • What does a voice VLAN not offer you?
  • In IPv6, what is the purpose of the link-local address?
  • Putting up signs serves as what type of control measure?
  • Which type of frame in WiFi announces SSID to the network?
  • What type of control is demonstrated by the use of a mantrap at the entrance of a facility?
  • Microsoft Windows file security permissions are an example of what?
  • To which aspect of web applications should developers pay special attention to prevent session hijacking?
  • What type of lock is considered more secure than standard locks for a facility?
  • In virtualization, what mechanism allows multiple VMs to share the same physical resources efficiently?
  • Which feature of virtualization allows multiple operating systems to run on a single hardware platform?
  • If a file has permissions set to 744, what access rights do the user, group, and world get?
  • Which of the following is true regarding cron jobs in the syslog configuration?
  • What might cause a tracert command to fail?
  • What security control would a border router typically implement?
  • RSA SecurID tokens provide what?
  • Which of these is NOT a reason for virtualizing?
  • What is a benefit of multifactor authentication?
  • What is the biggest problem with Bluetooth encryption?
  • How do viruses historically copy themselves from one system to another?
  • What type of attack does a firewall typically protect against?
  • What does the command 'umask' control in a Linux system?
  • Which strategy is recommended when using a quantitative risk assessment approach?
  • If you wanted to set up a quick wireless network between several devices for a LAN party, what might you do?
  • When is it most appropriate to conduct vulnerability scans?
  • What does the SID S-1-15-32-545 represent?
  • Which security model involves users having special privileges on a system?
  • What type of security framework does WPA2 utilize?
  • What is one outcome when an application has not addressed known vulnerabilities?
  • Which of the following is not a commonly used authentication factor?
  • What is the purpose of a bollard?
  • When advising on protecting a session ID in a web application, what is a recommended practice?
  • When creating a backup plan, which scheme would best balance recovery speed and storage space?
  • What is the primary function of a rootkit?
  • Kerberos tickets allow users to do what?
  • Which of the following is a reason why all vulnerabilities should not be addressed at once?
  • If you want to perform basic filtering on your network interface without a firewall, what should you establish?
  • Which of the following does 802.11i NOT address?
  • Which type of routing protocol uses the same algorithm as a car navigation system?
  • Which of the following VMWare files can be edited by hand in case of problems?
  • What technology does Microsoft Windows Update utilize to check for updates on a system?
  • Which of the following components does H.323 not specify in the networks?
  • What does NAT stand for in networking?
  • If your web browser generates a certificate error, which of the following is mostly likely to be the case?
  • Which of these is a significant advantage to deploying an IDS?
  • What does Java use to achieve architecture independence?
  • What type of malware is indicated by the presence of new files in the temp directory that record user inputs?
  • What is a good example of a network using a mesh topology?
  • To improve system security, which should be considered when installing applications?
  • In the network 192.168.5.0/23, what would be the broadcast address?
  • Which of the following protocols is used for secure communication over the internet?
  • Intrusion prevention systems provide an advantage over IDSs and anti-virus programs for what type of attack?
  • Users are encouraged to use a pin of how many characters in order to better protect their Bluetooth communications?
  • Which of the following is NOT typically considered a functionality of an intrusion detection system?
  • Which of the following is not a component of a SIP message?
  • Which component is critical for maintaining user access in a domain environment?
  • Which version of Windows 7 will NOT support connecting to Active Directory on your network?
  • After an evacuation, what is the best method to manage an airborne toxin?
  • Which statement best describes an access control list used by border routers?
  • How could you enforce your policy that all Bluetooth devices disable discoverable mode?
  • Which of the following is NOT an example of where an adversary can gather useful information?
  • How many phases does the Internet Key Exchange (IKE) have?
  • What type of fire occurs when ordinary combustibles, such as paper or wood, catch fire?
  • Many wireless technologies make use of one simple technology to prevent eavesdropping on the signal. What is it?
  • What type of attack is indicated by identical source and destination addresses in a packet?
  • Which protocol has historically been used by botnets for communication with handlers?
  • An effective risk management strategy may include which of the following?
  • When implementing a star topology on your local network, what type of cabling are you most likely to use?
  • Why is Halon no longer manufactured?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy