Practice for the GIAC Security Essentials (GSEC) exam with 14 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: Which of the following steps is NOT likely to occur during the recovery phase of an incident response?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.
Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the GSEC practice test →
What you will practice
- Which of the following steps is NOT likely to occur during the recovery phase of an incident response?
- What best describes the purpose of a company security policy?
- Your organization is concerned that an attack is being attempted against your Internet-facing Web server. Usi…
- You are seeking to discover the cause, type, and location of a violating event. Which of the following is the…
- What is a common security mechanism used to provide confidentiality?
- How can the integrity of a data file be verified?
Answers and explanations
Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.
Q1. Which of the following steps is NOT likely to occur during the recovery phase of an incident response?
Answer: B. B) Disconnecting systems from the Internet
Disconnecting systems typically happens during containment to isolate threats. The recovery phase focuses on restoring normal operations by applying patches, updating firmware, and validating authentication configurations.
Q2. What best describes the purpose of a company security policy?
Answer: C. C) Define the organization's security intentions and approach
A security policy defines an organization's security intentions and establishes its overall approach to protection. Punishing rule violators or preventing wasted resources might be beneficial outcomes, but they are not the primary purpose of the document.
Q3. Your organization is concerned that an attack is being attempted against your Internet-facing Web server. Using a network sniffer, you collected several thousand packets from the Internet-facing interface of the Web server in just one seco…
Answer: D. D) SYN flood
A hexadecimal value of 0x02 translates to binary 00000010, indicating the TCP SYN flag is set, which represents a SYN flood. For the exam, remember how to map protocol header flags to hexadecimal values to identify network attacks quickly.
Q4. You are seeking to discover the cause, type, and location of a violating event. Which of the following is the LEAST helpful data set to evaluate during the incident response investigation?
Answer: C. C) NTP synchronization logs
NTP synchronization logs are the least helpful because they primarily record time adjustments and rarely reveal direct attack evidence. In contrast, server, DHCP, and IDS logs provide critical context linking malicious activities to specific IP addresses and systems.
Q5. What is a common security mechanism used to provide confidentiality?
Answer: C. C) Symmetric encryption
Symmetric encryption provides confidentiality by ensuring only authorized parties with the correct key can access the data. Hashing provides integrity, while redundant servers and periodic backups primarily protect system and data availability.
Q6. How can the integrity of a data file be verified?
Answer: A. A) Compare before and after hash values.
You verify file integrity by comparing hash values generated before and after an event. Hashing detects unauthorized modifications, whereas backups restore damaged files and digital envelopes focus on securing data confidentiality.
Q7. What is the primary offensive goal of information warfare?
Answer: D. D) Corrupt an adversary's ability to act in their own interest
The primary offensive goal of information warfare is to corrupt an adversary's ability to make effective decisions and act in their own interest. A practical exam cue is to focus on the broad objective of decision disruption, whereas reconnaissance is merely a preparatory step.
Q8. For an incident response team to handle an incident, which of the following events must have occurred?
Answer: C. C) Identify the violating activity
An incident response team can only handle an incident after the violating activity has been identified. Detection and identification are absolute prerequisites, whereas patching systems or notifying customers are subsequent actions taken during later recovery phases.
Q9. How are malware attacks gaining access to victims' systems despite recent improvements in system security?
Answer: C. C) Taking advantage of social engineering
Malware increasingly bypasses technical security improvements by taking advantage of social engineering tactics. Attackers exploit human trust and curiosity because people are often the weakest link, making user training a critical defensive control.
Q10. When is triggering an internal incident response to handle a security breach the best option?
Answer: C. C) When company policy is violated and business tasks are affected
Internal incident response is triggered when policy violations impact business tasks. Automated defenses handle routine scanning or guessing attacks, and law enforcement handles criminal events.
Q11. What is the violation of availability?
Answer: A. A) Denial of service
Denial of service directly violates availability by preventing legitimate access to resources. Disclosure and leakage violate confidentiality, while corruption violates data integrity.
Q12. What is the basis of determining a user's permission on an object within a DAC system?
Answer: D. D) User identity
Discretionary access control bases permissions directly on user identity or group membership. Object classification is used for mandatory access control, while job roles define role-based access control.
Q13. Which of the following statements about a security policy is FALSE?
Answer: A. A) A security policy should be defined once and then enforced for at least a decade.
Security policies must remain flexible and be updated regularly as threats change, so decade-long enforcement is false. Policies require management support and universal compliance to maintain security effectively.
Q14. What is a definition of malicious code?
Answer: D. D) Software that causes unwanted harm, often automatically, once it infects a system
Malicious code is software that causes unwanted harm automatically once it infects a system. Remote control tools and password crackers are often classified as potentially unwanted programs rather than malware.
More GSEC drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.