Practice for the GIAC Security Essentials (GSEC) exam with 15 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following events would be most likely to trigger the activation of a disaster recovery plan?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the GSEC practice test →
What you will practice
- Which of the following events would be most likely to trigger the activation of a disaster recovery plan?
- Malware recovery and prevention is an expensive problem. Which of the following is a preventative cost associ…
- Which of the following is NOT typically a component of a security policy?
- Which of the following is NOT a reason why the final phase of incident response, lessons learned, is critical…
- Why are AAA services considered an essential security mechanism for a range of implementations, including man…
- Which of the following is an example of a vulnerability?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of the following events would be most likely to trigger the activation of a disaster recovery plan?
Answer: B. B) A flood in the basement server room
A disaster recovery plan is triggered when mission-critical business functions are interrupted. A data breach is an incident, while flooding a server room threatens operations and invokes recovery procedures.
Q2. Malware recovery and prevention is an expensive problem. Which of the following is a preventative cost associated with malware management?
Answer: C. C) Installing and updating anti-virus software
Installing and updating anti-virus software is a preventative cost associated with malware management. Post-infection damages like network downtime and lost productivity are reactive costs, not preventative measures.
Q3. Which of the following is NOT typically a component of a security policy?
Answer: A. A) Employee comments
Employee comments are not a formal component of a security policy framework. Policies, standards, guidelines, and procedures are the core documents used to define and enforce an organization's security posture.
Q4. Which of the following is NOT a reason why the final phase of incident response, lessons learned, is critical to the long-term success of an organization?
Answer: B. B) To prevent the spread of a violating event to other systems
The lessons learned phase focuses on documentation to improve future responses, train new team members, and support legal defense. Preventing an incident from spreading is the goal of the containment phase.
Q5. Why are AAA services considered an essential security mechanism for a range of implementations, including management of user access, program processing, remote access, and network connectivity?
Answer: D. D) AAA verifies unique identities and then holds them accountable for their actions.
AAA frameworks are essential because they verify unique identities and hold users accountable for their actions. It does not inherently encrypt communications, which requires separate protocols like TLS.
Q6. Which of the following is an example of a vulnerability?
Answer: C. C) Ports are kept open for nonessential services.
A vulnerability is a weakness that an attacker may discover and exploit. Open ports for nonessential services expand the attack surface, whereas malware and botnets represent threats or actors causing harm.
Q7. What is the purpose of authorization?
Answer: D. D) Control access to resources
Authorization controls access to resources based on the privileges granted to a verified user. Exam candidates must carefully distinguish this from authentication, which merely verifies identity, or accounting.
Q8. Which of the following can detect a wireless network?
Answer: D. D) Eavesdropping on beacon frames
Eavesdropping on beacon frames allows devices to detect wireless networks broadcasting in the area. Ping sweeps and port scans require an existing network connection and cannot discover disconnected networks.
Q9. How can you reduce the risk of exploitation of your organization related to social engineering attacks?
Answer: B. B) Strongly encourage workers to always follow company policy, regardless of what someone over the phone or via email demands.
Strongly encouraging workers to follow company policy reduces social engineering risks by preventing attackers from bypassing rules. Technical controls like encryption do little to stop an attacker manipulating human trust.
Q10. How can vulnerabilities in personnel be most effectively addressed?
Answer: B. B) Training and awareness
Security vulnerabilities in personnel are most effectively addressed through ongoing security training and awareness programs. Technical controls like firewalls and encryption do not mitigate human weaknesses, so remember that human manipulation requires human-focused defenses.
Q11. Why is the role of authorization important in AAA services?
Answer: B. B) It sets boundaries for allowed activities.
Authorization is important because it sets the specific boundaries for what activities an authenticated user is allowed to perform. Do not confuse this with authentication, which merely verifies identity, or auditing, which monitors actions after the fact.
Q12. Which of the following is a true statement?
Answer: C. C) DAC is decentralized.
Discretionary access control is decentralized because data owners manage permissions directly through access control lists on their objects. A strong exam cue is that mandatory access control is centralized and rigid, whereas discretionary access control distributes control.
Q13. Why is an evil twin attack so effective?
Answer: B. B) It mimics the identity of a trusted WAP.
An evil twin attack is effective because it mimics the identity of a trusted wireless access point to trick devices into connecting. Clients automatically favor the strongest signal matching a saved profile, allowing the attacker to intercept traffic easily.
Q14. Who should NEVER be involved in collecting evidence during an investigation or an incident response?
Answer: B. B) An untrained employee
An untrained employee should never collect evidence because they are likely to damage its integrity or break the chain of custody. Proper evidence handling requires forensically trained personnel to ensure the data remains admissible in legal proceedings.
Q15. What tool is commonly used to perform port scans, OS identification, and version or banner grabbing against services?
Answer: B. B) nmap
Nmap is the standard network mapping tool used for port scanning, OS fingerprinting, and banner grabbing. Aircrack targets wireless encryption, while Cain and Abel focuses on password cracking.
More GSEC drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.