(2023) PASS GSEC exam with GIAC GSEC Real Exam Questions
Real exam questions are provided for GIAC Information Security tests, which can make sure you 100% pass
GIAC GSEC exam is a renowned certification for professionals seeking to advance their career in the field of cybersecurity. It is an entry-level exam designed to test the candidate's knowledge of basic security concepts and skills. GIAC Security Essentials Certification certification is widely recognized in the industry and is a valuable asset for those looking to enhance their resumes and demonstrate their expertise in the field.
NEW QUESTION # 51
While using Wire shark to investigate complaints of users being unable to login to a web application, you come across an HTTP POST submitted through your web application. The contents of the POST are listed below. Based on what you see below, which of the following would you recommend to prevent future damage to your database?
- A. Authenticate users to prevent hackers from using your database
- B. Use ssh to prevent a denial of service attack
- C. Sanitize user inputs to prevent injection attacks
- D. Use https to prevent hackers from inserting malware
Answer: D
NEW QUESTION # 52
Which of the following is NOT typically used to mitigate the war dialing threat?
- A. Setting up monitored modems on special phone numbers
- B. Proactively scanning your own phone numbers
- C. Monitoring call logs at the switch
- D. Setting modems to auto-answer mode
Answer: D
NEW QUESTION # 53
Which of the following protocols provides maintenance and error reporting function?
- A. IGMP
- B. UDP
- C. ICMP
- D. PPP
Answer: C
NEW QUESTION # 54
Which of the following is a type of countermeasure that can be deployed to ensure that a threat vector does not meet a vulnerability?
- A. Detection controls
- B. Prevention controls
- C. Subversive controls
- D. Monitoring controls
Answer: B
NEW QUESTION # 55
What is the term for a game in which for every win there must be an equivalent loss?
- A. Gain-oriented
- B. Untenable
- C. Zero-sum
- D. Asymmetric
Answer: C
NEW QUESTION # 56
Which of the following statements about service pack are true? Each correct answer represents a complete solution. Choose two.
- A. It is a medium by which product updates are distributed.
- B. It is a collection of Fixes and Patches in a single product.
- C. It is a term used for securing an operating system.
- D. It is a term generally related to security problems in a software.
Answer: A,B
NEW QUESTION # 57
Which of the following can be done over telephone lines, e-mail, instant messaging, and any other method of communication considered private.
- A. Spoofing
- B. Packaging
- C. Eavesdropping
- D. Shielding
Answer: C
NEW QUESTION # 58
Which of the following tools is used to configure, control, and query the TCP/IP network interface parameters?
- A. IPCONFIG
- B. IFCONFIG
- C. ARP
- D. NSLOOKUP
Answer: B
NEW QUESTION # 59
What does PowerShell remoting use to authenticate to another host in a domain environment?
- A. Two factor codes
- B. Unique application passwords
- C. PreShared keys
- D. Kerberos tickets
Answer: D
NEW QUESTION # 60
Which Defense-in-Depth model involves identifying various means by which threats can become manifest and providing security mechanisms to shut them down?
- A. Uniform protection
- B. Protected enclaves
- C. Information centric defense
- D. Vector-oriented
Answer: D
NEW QUESTION # 61
A Host-based Intrusion Prevention System (HIPS) software vendor records how the Firefox Web browser interacts with the operating system and other applications, and identifies all areas of Firefox functionality. After collecting all the data about how Firefox should work, a database is created with this information, and it is fed into the HIPS software. The HIPS then monitors Firefox whenever it's in use. What feature of HIPS is being described in this scenario?
- A. Signature Matching
- B. Host Based Sniffing
- C. Application Action Modeling
- D. Application Behavior Monitoring
Answer: D
NEW QUESTION # 62
Which of the following focuses on identifying weaknesses within the current system?
- A. Vulnerability scanning
- B. Virus scanning
- C. Network scanning
- D. Active port scanning
Answer: A
NEW QUESTION # 63
What is a limitation of deploying HIPS on a workstation?
- A. Restricted support for custom applications
- B. Requires an HIDS to Identify an attack
- C. Requires more frequent system patching
- D. Runs as a non-privileged user
Answer: A
NEW QUESTION # 64
You work as a Web Developer for WebCrunch Inc. You create a web site that contains information about the company's products and services. The web site is to be used by the company's suppliers only. Which of the following options will you use to specify the nature of access to the web site?
- A. Intranet
- B. Extranet
- C. Internet and Intranet
- D. Internet
Answer: B
NEW QUESTION # 65
Which of the following ports is used by the Secure File Transfer Protocol (SFTP)?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 66
You are doing some analysis of malware on a Unix computer in a closed test network. The IP address of the computer is 192.168.1.120. From a packet capture, you see the malware is attempting to do a DNS query for a server called iamabadserver.com so that it can connect to it. There is no DNS server on the test network to do name resolution. You have another computer, whose IP is 192.168.1.115, available on the test network that you would like for the malware connect to it instead. How do you get the malware to connect to that computer on the test network?
- A. You modify the HOSTS file on the computer you want the malware to connect to and add an entry that reads: 192.168.1.115 iamabadserver iamabadserver.com
- B. You modify the HOSTS file on the Unix computer your malware is running on and add an entry that reads:
192.168.1.120 iamabadserver iamabadserver.com - C. You modify the HOSTS file on the Unix computer your malware is running on and add an entry that reads:
192.168.1.115 iamabadserveriamabadserver.com - D. You modify the HOSTS file on the computer you want the malware to connect to and add an entry that reads: 192.168.1.120 iamabadserver iamabadserver.com
Answer: C
NEW QUESTION # 67
Which Host-based IDS (HIDS) method of log monitoring utilizes a list of keywords or phrases that define the events of interest for the analyst, then takes a list of keywords to watch for and generates alerts when it sees matches in log file activity?
- A. Passive analysis
- B. Inclusive analysis
- C. Retroactive analysis
- D. Exclusive analysis
Answer: B
NEW QUESTION # 68
Which of the following is TRUE regarding Ethernet?
- A. Ethernet is shared media.
- B. Stations are not required to listen before they transmit.
- C. Several stations are allowed to be transmitting at any given time within a single collision domain.
- D. Stations are not required to monitor their transmission to check for collisions.
Answer: A
NEW QUESTION # 69
Which of the following statements about buffer overflow are true? Each correct answer represents a complete solution. Choose two.
- A. It is a situation that occurs when a storage device runs out of space.
- B. It can terminate an application.
- C. It can improve application performance.
- D. It is a situation that occurs when an application receives more data than it is configured to accept.
Answer: B,D
NEW QUESTION # 70
What is the function of the TTL (Time to Live) field in IPv4 and the Hop Limit field in IPv6 In an IP Packet header?
- A. These fields are initialized to an initial value to prevent packet fragmentation and fragmentation attacks.
- B. These fields are incremented each time a packet is transmitted to indicate the number of routers that an IP packet has traversed.
- C. These fields are decremented each time a packet is retransmitted to minimize the possibility of routing loops.
- D. These fields are recalculated based on the required time for a packet to arrive at its destination.
Answer: C
NEW QUESTION # 71
Which of the following protocols is used to retrieve e-mails from a remote mail server?
- A. SNMP
- B. SMTP
- C. IGMP
- D. POP3
Answer: D
NEW QUESTION # 72
When trace route fails to get a timely response for a packet after three tries, which action will it take?
- A. It will exit gracefully, and indicate to the user that the destination is unreachable.
- B. It will print '* * *' for the attempts, increment the TTL and try again until the maximum hop count.
- C. It will print '* * *' for the attempts and increase the maximum hop count by one.
- D. It will increase the timeout for the hop and resend the packets.
Answer: B
NEW QUESTION # 73
......
The GSEC certification exam is administered by the Global Information Assurance Certification (GIAC), which is part of the SANS Institute, a leading provider of cybersecurity training and certification. The GSEC certification exam is designed to test the knowledge and expertise of security professionals in various areas of information security, including networking, cryptography, access controls, and security policy development. GSEC exam is intended for professionals who have at least two years of experience in the field of information security.
Latest GSEC Pass Guaranteed Exam Dumps Certification Sample Questions: https://freedumps.actual4exams.com/GSEC-real-braindumps.html