Browse all practice questions for the GIAC Security Essentials Certification (GSEC) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GIAC Security Essentials Certification (GSEC) Practice Test 2026 - Free GSEC Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • A very primitive but popular type of encryption cipher is called what?
  • Which statement best describes an access control list used by border routers?
  • What security control would a border router typically implement?
  • What is one outcome when an application has not addressed known vulnerabilities?
  • What type of attack is indicated by identical source and destination addresses in a packet?
  • Which of the following can be used to authenticate someone?
  • Which feature of virtualization allows multiple operating systems to run on a single hardware platform?
  • What is a translation lookaside buffer used for?
  • Which of the following is NOT a reason for packing a program?
  • Which of the following protocols is used for secure communication over the internet?
  • If you want to perform basic filtering on your network interface without a firewall, what should you establish?
  • What do intrusion detection systems NOT need in order to operate effectively?
  • What type of lock is considered more secure than standard locks for a facility?
  • Which term describes software that is designed to exploit vulnerabilities in computers or networks?
  • Which version of Windows 7 will NOT support connecting to Active Directory on your network?
  • In the address ab00:fc87:234a:0090:5120:ffab:bc8a:0098/23, what does the /23 indicate?
  • How do viruses historically copy themselves from one system to another?
  • If you observe unusual network traffic originating from your computer to foreign IPs, what could this suggest?
  • Which of the following is not a commonly used authentication factor?
  • To improve system security, which should be considered when installing applications?
  • If your web browser generates a certificate error, which of the following is mostly likely to be the case?
  • Why is Halon no longer manufactured?
  • What technology does Microsoft Windows Update utilize to check for updates on a system?
  • Which security measure is designed to protect a network by blocking unauthorized access while permitting outward communication?
  • What might cause a tracert command to fail?
  • What is the primary function of a firewall?
  • Which protocol has historically been used by botnets for communication with handlers?
  • To conduct static analysis on a piece of malware, what is a possible action?
  • Which of the following best describes spyware?
  • What security solution would you implement to prevent employees from browsing Facebook during work hours?
  • Which of the following is an example of a passive security measure?
  • What type of engineering is utilized by malware?
  • What is the best way to protect data at rest?
  • What should your first action be before conducting an unscheduled vulnerability scan?
  • In which scenario is ARP spoofing most likely occurring?
  • Which of these would be considered the most important part of cryptography?
  • How are security policies best described?
  • Which of these is a common method to enhance physical security in sensitive areas?
  • Which of the following is NOT typically considered a functionality of an intrusion detection system?
  • Which of the following does 802.11i NOT address?
  • What is the principle of least privilege implemented in?
  • What is a common use of Group Policy in a Windows environment?
  • What technology is often used to enhance security in virtual environments?
  • In the context of cybersecurity, what does the term "threat landscape" refer to?
  • Adding an additional alphanumeric character to the required length of a password will multiply the potential passwords by how many?
  • Which of the following tactics might allow a perpetrator to gain a lot of information from a device?
  • How can you enhance a group’s security permissions in Active Directory?
  • Authentication is the process of doing what?
  • Without virtual memory, what were programmers typically required to use?
  • What key combination generates a SIGINT signal in a terminal?
  • What does Microsoft recommend for assigning permissions to a set of users?
  • What can you infer if all results of a port scan show filtered ports?
  • A substitution steganography uses this part of a carrier file.
  • How many phases does the Internet Key Exchange (IKE) have?
  • Which action is likely to help prevent infections from viruses?
  • After an evacuation, what is the best method to manage an airborne toxin?
  • Which form of attack is specifically designed to exploit weaknesses in Bluetooth?
  • What type of attack is typically characterized by overwhelming a system with traffic to disrupt services?
  • What is a common characteristic of adware?
  • H.245 is used for what aspects of an H.323 session?
  • Your intrusion detection system has alerted you that you are getting a SIP attack. What would you consider this attack to be, based solely on the information you have?
  • What type of lock would be appropriate for securing a facility during unoccupied hours?
  • What is the primary difference between a virus and a worm?
  • Your boss wants to fix a critical vulnerability on the database server immediately. What should you do?
  • Skype uses what type of communication to connect its users?
  • Which of the following VMWare files can be edited by hand in case of problems?
  • What tool would you use to enable auditing on systems in your network?
  • Which type of frame in WiFi announces SSID to the network?
  • What component does water primarily remove to extinguish a fire?
  • What can John the Ripper be used for?
  • When advising on protecting a session ID in a web application, what is a recommended practice?
  • According to the syslog configuration, where are login messages stored?
  • What class is the address 170.19.82.45?
  • An effective risk management strategy may include which of the following?
  • What does the SSID stand for in a wireless network context?
  • When is it most appropriate to conduct vulnerability scans?
  • When implementing a star topology on your local network, what type of cabling are you most likely to use?
  • What is the primary function of a rootkit?
  • What does a vulnerability scan that identifies a firewall indicate?
  • Which technology allows you to block network access based on the application being used to initiate the request?
  • Which of the following is not a benefit of VoIP?
  • Backups and replication are two strategies primarily used for what purpose?
  • Your bank is implementing a token-based solution for authentication. What type of authentication will they be using?
  • Which of the following is NOT an example of where an adversary can gather useful information?
  • What is the main function of a firewall?
  • RSA SecurID tokens provide what?
  • What are significant challenges for intrusion detection systems?
  • Which security principle emphasizes the need to limit user access rights to the bare minimum?
  • When creating a backup plan, which scheme would best balance recovery speed and storage space?
  • What is the benefit of using snapshots in virtualization?
  • Which decade saw the creation of the first virtual machines?
  • If recyclables ignite due to high temperatures, what class of fire would this represent?
  • What was SIP developed for?
  • SQL Injection attacks are targeted at what?
  • Which of the following components does H.323 not specify in the networks?
  • Which type of routing protocol uses the same algorithm as a car navigation system?
  • What can be a major downside of using compression in an intrusion detection system?
  • Which security model involves users having special privileges on a system?
  • Which utility would you use to monitor CPU usage of individual processes updated every three seconds?
  • If your vulnerability scan shows your Web server is vulnerable, but you are running version 2.6 of that software, what might be the reason?
  • Public key algorithms are also called what?
  • If the SLE for a system is $5,000 and the ARO is 2, what is the ALE?
  • Which of the following best defines a Denial of Service (DoS) attack?
  • What is the subnet mask for the address block 10.1.0.0 with a /24 prefix?
  • How would you define the host operating system?
  • What can you accomplish by hiding your SSID?
  • Which VMWare product is available for free to run virtual machines?
  • What is the primary goal of an incident response plan?
  • Which method can improve the security of a WiFi network?
  • What is a common use case for virtualizing servers?
  • What is the main purpose of using a hashing algorithm in password storage?
  • What might be a sign that malware is present on a system?
  • What are two primary responsibilities of the hypervisor?
  • Which of these is NOT a reason for virtualizing?
  • How should you prioritize the list of vulnerabilities from a Nexpose scan?
  • Putting up signs serves as what type of control measure?
  • Many wireless technologies make use of one simple technology to prevent eavesdropping on the signal. What is it?
  • What functionality does TripWire provide in terms of security?
  • Which of the following is a private address (RFC1918)?
  • What is the most important criterion when deploying an intrusion prevention system on your network?
  • Which of the following practices is crucial for maintaining data integrity during data storage?
  • Intrusion prevention systems provide an advantage over IDSs and anti-virus programs for what type of attack?
  • A session border controller can help with which of the following security situations?
  • Which component is critical for maintaining user access in a domain environment?
  • With the following IP header, what is the destination IP address: 45 00 03 3D 1E EB 40 00 40 06 5D E8 C0 A8 01 16 AD C2 4B 67?
  • Which method is ineffective in breaking the security of a physical barrier?
  • What type of backup retains all data regardless of previous backups?
  • In what format are Windows Firewall logs stored?
  • Which command would you use in a batch file to make changes to the Windows registry?
  • What does a voice VLAN not offer you?
  • When creating a vulnerability scanning schedule for a large network, what is an effective strategy?
  • What does the command 'umask' control in a Linux system?
  • What concept ensures that only the necessary privileges are granted to users?
  • Which of the following is not a component of a SIP message?
  • Which type of authentication does SIP use?
  • How could you enforce your policy that all Bluetooth devices disable discoverable mode?
  • What can you say about the following packet capture: 14:18:25.906002 apollo.it.luc.edu.1000 > x-terminal.shell: S...?
  • The SUBSCRIBE message can be used for what purpose?
  • What is the purpose of the 'htop' utility?
  • What is the primary use of a spike strip in security?
  • The challenge of trying to find a collision in a hashing algorithm is called what?
  • If you observe many ARP responses without matching ARP requests, what are you likely witnessing?
  • What does PAM do to protect password security?
  • Why might a UDP scan take longer to complete than other types of scans?
  • If you see the IP address fe80::0050:8790:4554:2300/16, what does the :: indicate?
  • What is the primary benefit of using WPA over WEP?
  • What type of security framework does WPA2 utilize?
  • What type of fire occurs when ordinary combustibles, such as paper or wood, catch fire?
  • What is the primary function of an intrusion detection system?
  • Users are encouraged to use a pin of how many characters in order to better protect their Bluetooth communications?
  • Your firewall has a rule blocking inbound ICMP messages unless they are responses to a request originated from inside the network. Which attack is most likely being protected against?
  • Embedded wires in glass are designed to achieve which of the following?
  • What's the difference between virtualization and emulation?
  • For which of the following scenarios would a deterrent control be most appropriate?
  • If you wanted to generate keys in a secure fashion to exchange encrypted information, which process would you use?
  • What type of control is demonstrated by the use of a mantrap at the entrance of a facility?
  • In virtualization, what mechanism allows multiple VMs to share the same physical resources efficiently?
  • What is the order of messages in a three-way handshake?
  • In the network 192.168.5.0/23, what would be the broadcast address?
  • Which command would you use to view the current running processes?
  • Which of the following is true regarding cron jobs in the syslog configuration?
  • What does Java use to achieve architecture independence?
  • The frequent appearance of popup ads while browsing the web is an indication of what type of malware?
  • What is a common way in which ransomware operates?
  • What is the purpose of a bollard?
  • What type of malware is indicated by the presence of new files in the temp directory that record user inputs?
  • If you wanted to set up a quick wireless network between several devices for a LAN party, what might you do?
  • In response to SQL injection errors detected in a commercial web application, which action would NOT be a part of remediation?
  • If a file has permissions set to 744, what access rights do the user, group, and world get?
  • What are Duqu and Stuxnet examples of?
  • Which of the following will help protect a Web application infrastructure from Web attacks like SQL Injection?
  • If your IDS alerts you about a packet with the same source and destination, what could this indicate?
  • Where would you find statistics on the inet process with process ID 1 in your filesystem?
  • Which utility makes use of ICMP to function?
  • PGP uses what sort of system to verify the identity of the certificate holder?
  • Which strategy is recommended when using a quantitative risk assessment approach?
  • What does the SID S-1-15-32-545 represent?
  • In order to validate a certificate presented to you, what would you need?
  • What is a good example of a network using a mesh topology?
  • How many bits are in the NETWORK portion of the following address block: Address: 10.1.0.0, Subnet: 255.255.255.224?
  • In IPv6, what is the purpose of the link-local address?
  • Which of these is a significant advantage to deploying an IDS?
  • Which of the following is a reason why all vulnerabilities should not be addressed at once?
  • Kerberos tickets allow users to do what?
  • To determine whether a project makes financial sense, you would perform which of these?
  • What type of attack does a firewall typically protect against?
  • Microsoft Windows file security permissions are an example of what?
  • What is a benefit of multifactor authentication?
  • Vulnerability scanners do NOT do which of the following?
  • Which command is used to set file permissions in Linux?
  • What does NAT stand for in networking?
  • Network devices and dialup users may be authenticated using which of the following protocols?
  • Which file contains mappings between ports and the names of applications associated with them?
  • What does an organization need to ensure both complete operations recovery and continued operations?
  • If vulnerability scans are routinely run but no one is reviewing the reports, what can be said about those scans?
  • What effect does the iptables rule 'iptables -A INPUT -j DROP' have on network traffic?
  • What is a key advantage of a boot sector virus?
  • To which aspect of web applications should developers pay special attention to prevent session hijacking?
  • What is the biggest problem with Bluetooth encryption?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy