GIAC · Free Practice Questions · Last reviewed May 2026
156real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A security analyst needs to capture raw packet data from a high-speed core switch to analyze suspicious east-west traffic movements without interrupting production data flows. Which device feature should be configured on the switch?
Network Address Translation (NAT) overloading
Switched Port Analyzer (SPAN) or port mirroring
SPAN copies frames from selected switch ports or VLANs to a monitoring port, giving passive visibility of east-west traffic without inline interception. This satisfies the constraint of capturing raw packets while production flows continue uninterrupted.
Virtual Router Redundancy Protocol (VRRP) failover
Dynamic Host Configuration Protocol (DHCP) snooping
An organization deploys a network-based Intrusion Detection System (IDS) in passive monitoring mode on a core switch trunk link. If the IDS detects an active external command-and-control connection to an infected internal workstation, what action does the IDS take?
It automatically injects TCP reset (RST) packets into the stream to terminate the active session.
It drops the malicious packets at the interface level to protect the internal workstation from further compromise.
It generates an alert log entry and notifies security analysts via SIEM integration or SNMP traps.
Passive IDS sensors monitor mirrored traffic without interfering with packet delivery. Upon detecting malicious indicators, they record the event to local logs and transmit alerts to centralized management systems and SIEM platforms for analyst review.
It dynamically updates the core switch routing table to quarantine the infected workstation into an isolated VLAN.
Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?
The traffic is permitted because the second rule matches the source subnet.
The traffic is denied because the first rule matches and terminates evaluation.
The router processes the ACL in a top-down fashion. The first rule denies all traffic to 10.0.5.5 on port 80. Since the packet matches this criteria, the evaluation stops, and the router silently discards the packet. The permit rule located on the second line is never reached.
The traffic is permitted because permit rules take precedence over deny rules.
The router generates an error because the ACL rules are contradictory.
A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?
Verify the IPS can perform inspection at line rate with low latency and has a hardware bypass mechanism to maintain availability if it fails.
For an inline IPS on a high-speed clinical link, the device must handle 10 Gbps of traffic without adding latency that affects real-time monitoring. A hardware bypass or fail-to-wire capability ensures that if the IPS fails or loses power, traffic continues to flow, preserving patient safety. This combination of performance and availability is the primary deployment consideration for this scenario.
Configure the IPS in tap mode with a fail-open bypass so it can inspect traffic without being in the forwarding path.
Enable full packet capture on the IPS to record all traffic for forensic analysis, accepting the performance overhead.
Deploy the IPS in promiscuous mode and rely on span ports to mirror traffic from the core switch.
A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?
Stateful inspection with session tracking
Stateful inspection maintains a session table that tracks the state of each connection. When an outbound connection is initiated, the firewall creates an entry, and return traffic matching that session is automatically allowed. If session tracking is disabled or the table is full, return packets may be dropped. This feature is essential for allowing return traffic without explicit inbound rules.
Access control lists (ACLs) applied to the inbound interface
Deep packet inspection (DPI) with application signatures
Network address translation (NAT) with port forwarding
A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?
Deploy the appliance as a routed hop between the two VLANs with a static route on each side.
Deploy a TAP aggregator that mirrors both VLANs to the appliance and enable fail-open on the NIC.
Deploy a Layer 2 bridge running in inline mode with a hardware bypass fail-to-wire segment.
An inline Layer 2 bridge inspects traffic between the two VLANs while remaining transparent to IP addressing, and a hardware bypass fail-to-wire segment physically shunts packets around the appliance if it loses power, preserving connectivity for clinical systems. This directly satisfies both the inspection and the survivability requirements without renumbering hosts or altering routing.
Deploy a SPAN port on the core switch and attach the appliance in passive monitor-only mode.
Want more Network Security Devices practice?
Practice this domainAn administrator needs to restrict sensitive file access on a Windows Server 2022 environment while ensuring that users only access resources based on their job titles. Which Windows technology should be implemented to leverage Dynamic Access Control (DAC) for this requirement?
Implement Kerberos Constrained Delegation
Configure Central Access Policies
Central Access Policies are the core component of Dynamic Access Control. They allow administrators to define resource authorization policies centrally in Active Directory and apply them to files and folders using resource properties, effectively enforcing access based on user attributes like department or job title globally.
Apply AppLocker Software Restriction Policies
Utilize Encrypting File System (EFS)
When analyzing Windows event logs to detect brute-force activity, which Event ID indicates a failed logon attempt?
Event ID 4624
Event ID 4625
Event ID 4625 is the definitive log entry for a failed logon attempt in the Windows Security event log. It contains valuable metadata such as the username, source IP address, and logon type, which are necessary for identifying the origin and target of a brute-force attack.
Event ID 4740
Event ID 4768
An organization is deploying Just-In-Time (JIT) administration. Which Windows feature provides the necessary framework for creating temporary, elevated group memberships for domain administrators?
Restricted Groups GPO
Privileged Access Management (PAM)
PAM provides the capability to grant time-limited, Just-In-Time administrative access. By utilizing shadow principals and the MIM platform, organizations can provision temporary group memberships, ensuring that administrative accounts do not remain privileged indefinitely, which significantly mitigates the risk associated with account compromise.
User Rights Assignment policy
Group Policy Preferences
When configuring an Active Directory (AD) environment, which functional level is required to utilize the 'Authentication Policies' feature introduced in Windows Server 2012?
Windows Server 2003
Windows Server 2008 R2
Windows Server 2012
The Windows Server 2012 domain functional level is the minimum requirement to enable Authentication Policies. This feature allows administrators to restrict which hosts an account can authenticate to, which is a powerful mechanism for limiting the blast radius of a compromised credential within the domain environment.
Windows Server 2016
Which component of the Windows Security Infrastructure is responsible for checking the user's token against the Security Descriptor of an object to authorize access?
Local Security Authority (LSA)
Security Reference Monitor (SRM)
The SRM is the kernel-mode component that enforces access control. It validates the user's access token against the DACL on a requested object. It is the definitive authority for authorization decisions within the Windows operating system, ensuring that permissions are strictly followed for all resource access requests.
Security Account Manager (SAM)
Active Directory Domain Services (AD DS)
A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?
Network security: Restrict NTLM: NTLM authentication in this domain
This setting allows you to deny NTLM authentication for domain accounts. When set to 'Deny all,' it blocks NTLM authentication requests for domain accounts, forcing Kerberos. This directly addresses the scenario by preventing NTLM use entirely within the domain.
Network security: LAN Manager authentication level
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
Network security: Configure encryption types allowed for Kerberos
Want more Windows Security Infrastructure practice?
Practice this domainAn organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?
FileVault 2
Gatekeeper
System Integrity Protection (SIP)
System Integrity Protection restricts the root user from modifying protected locations like /System, /bin, and /usr. By enforcing signed kernel extensions and preventing unauthorized modifications to system processes, it directly protects the kernel integrity, ensuring that only trusted, Apple-approved code can operate at the system core level.
XProtect
Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?
Modifying files within the /System directory
The /System directory contains core macOS components that are essential for system stability and security. SIP explicitly prevents the root user from writing to or modifying files in this path, ensuring that core binaries and libraries remain untampered throughout the lifecycle of the operating system.
Installing unsigned applications from the internet
Loading unsigned kernel extensions (kexts)
SIP mandates that only kernel extensions signed by a valid Apple Developer ID may be loaded. This prevents malicious actors from loading unsigned rootkits or drivers that could bypass security controls. By enforcing cryptographic signatures for kexts, the system maintains a secure chain of trust at the kernel level.
Accessing user-defined keychain items
Encrypting the user home directory
Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?
The endpoint is vulnerable to root-level system file modification.
The endpoint's kernel integrity protections are actively enforced.
When SIP status is reported as enabled, the kernel is protected from unsigned extensions and unauthorized modifications. This is the intended behavior for a secure macOS deployment, ensuring that only trusted components can execute at the lowest levels of the operating system, thereby mitigating risks from malicious drivers.
The disk encryption configuration is currently failing.
The device has been successfully compromised by a kernel rootkit.
A user reports they cannot open a downloaded application because macOS states the developer cannot be verified. Which security feature is preventing the execution of this application?
XProtect
Gatekeeper
Gatekeeper is the security feature that checks if an application is signed by an identified developer and notarized by Apple. If an application fails these checks, Gatekeeper prevents it from executing to ensure that the software has not been altered or created by an untrusted entity.
System Integrity Protection
FileVault 2
What is the primary purpose of the 'Notarization' process for macOS applications?
To provide full-disk encryption for the application data.
To scan for malicious code and verify developer identity.
Notarization uses automated tools to scan applications for known malware and verify that they are properly signed by a verified Apple Developer account. This ensures that users are protected from installing malicious software, acting as a crucial pre-execution security check for all macOS applications.
To restrict application access to user contact data.
To enforce system-level integrity of the kernel.
A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?
XProtect
Gatekeeper
Gatekeeper is the macOS feature that verifies the authenticity and integrity of applications downloaded from the internet. It checks whether the app is notarized by Apple and signed with a valid Developer ID. If the app cannot be verified, Gatekeeper blocks it from launching, which matches the scenario. This is the primary defense against malware disguised as legitimate software.
System Integrity Protection (SIP)
Transparency, Consent, and Control (TCC)
Want more macOS Security practice?
Practice this domainA security engineer is designing an internal Public Key Infrastructure (PKI) and needs to issue a subordinate certificate authority (sub-CA) certificate. To prevent this sub-CA from accidentally or maliciously issuing certificates for unauthorized domains, what specific X.509 extension must be correctly configured?
Key Usage extension populated solely with Digital Signature, Non-Repudiation, and Key Encipherment flags.
Authority Information Access extension pointing directly to the organization's primary online OCSP responder.
Name Constraints extension configured with explicit permitted and excluded subtree subdirectories for domain namespaces.
Name Constraints enforce strict boundaries on subordinate CAs by defining exact permitted and excluded domain namespaces. If a sub-CA attempts to issue a certificate outside these boundaries, relying parties will immediately reject it as invalid.
Extended Key Usage extension restricted strictly to TLS Web Server Authentication and Code Signing.
An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is maintained for all incoming sessions. Which underlying key exchange mechanism should be prioritized in the configuration?
RSA key transport mechanism
Elliptic Curve Diffie-Hellman Ephemeral
ECDHE leverages transient elliptic curve parameters for each unique handshake transaction. Because the server private key is only used to digitally sign the ephemeral exchange and is never used to derive the session key directly, past sessions remain entirely secure against future key compromises.
Pre-Shared Key authentication mode
Static Diffie-Hellman key agreement
A security analyst is hardening a web server to ensure that only modern, secure protocols are used for HTTPS traffic. Which configuration best aligns with GSEC security standards for data in transit?
Support TLS 1.0, 1.1, and 1.2 to maintain maximum backward compatibility.
Enable SSLv3 for clients who cannot support newer TLS versions.
Disable SSL and TLS 1.0/1.1, allowing only TLS 1.2 and 1.3.
Restricting traffic to TLS 1.2 and 1.3 eliminates the usage of deprecated, insecure ciphers and handshake methods. This configuration adheres to current industry best practices and compliance frameworks, effectively closing the window on several classes of protocol downgrade attacks that plague older implementations of the HTTPS stack.
Use RC4 for all connections to ensure high performance over low-bandwidth links.
An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?
Use SHA-256 hashing for all database fields.
Implement AES-256 in GCM mode.
AES-256 in GCM mode offers high-speed, symmetric encryption that ensures confidentiality while simultaneously providing integrity through an authentication tag. This approach satisfies the dual requirements of reversibility for authorized users and protection against data tampering, which is the gold standard for protecting sensitive database records in modern systems.
Use RSA-4096 for encrypting large datasets.
Apply XOR-based encryption with a static global key.
Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?
Centralized distribution of symmetric keys.
Issuance of digital certificates to verify identity.
Issuing digital certificates is a core function of the Certificate Authority (CA) within a PKI. These certificates bind a public key to a specific entity, allowing other parties to verify that the entity is who they claim to be, which is fundamental to establishing trust online.
Revocation of compromised or invalid certificates.
Certificate revocation is a mandatory function of PKI. When a private key is compromised or a certificate is no longer needed, the CA must publish this information via Certificate Revocation Lists (CRLs) or OCSP, ensuring that untrusted or fraudulent certificates are no longer accepted by relying parties.
Hardware-level encryption for disk storage.
Real-time traffic flow monitoring and alerting.
When selecting a cryptographic hash function for verifying file integrity, which property is most important to ensure that an attacker cannot create two different files that produce the same hash value?
Pre-image resistance.
Collision resistance.
Collision resistance specifically addresses the difficulty of finding any two distinct inputs that map to the same hash value. This prevents attackers from creating a 'doppelganger' file that passes integrity checks designed for a known-good file, which is a key requirement for secure file verification and distribution systems.
Reversibility.
High computational speed.
Want more Cryptography Application practice?
Practice this domainAn organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?
Least Privilege
Security through Obscurity
Defense in Depth
Defense in depth is an information security strategy that integrates multiple layers of security controls throughout an IT system. Its primary goal is to protect data by ensuring that if an attacker bypasses one defense, subsequent layers remain to prevent unauthorized access or minimize the overall impact.
Fail-Safe Defaults
Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?
To eliminate the need for regular security patching.
To increase the difficulty and cost for an attacker to succeed.
By implementing multiple, heterogeneous layers of security, an organization forces an attacker to expend more time and resources. Each additional layer increases the complexity of the attack chain, raising the likelihood of detection and providing more opportunities for the security team to identify and stop the adversary.
To ensure that a single control failure does not result in a breach.
The core of defense in depth is redundancy. By ensuring that no single security measure is a single point of failure, the organization can contain threats. If a firewall is bypassed, host-based security or network segmentation serves as the next barrier to stop the attacker from moving laterally.
To replace the requirement for user security awareness training.
To centralize all logs into a single storage location.
Which of the following represents an example of applying defense in depth at the host level?
Installing a web application firewall at the network edge.
Configuring local host firewalls and endpoint detection and response (EDR) software.
These two tools together at the host level create a layer of defense that operates independently of network-wide controls. The host firewall limits incoming and outgoing traffic, while EDR provides continuous monitoring and threat prevention for local processes, effectively creating a defense in depth posture on the machine.
Implementing multi-factor authentication for corporate VPN access.
Deploying a network intrusion detection system (NIDS) in promiscuous mode.
When designing a defense in depth strategy, why is it recommended to use heterogeneous security controls rather than homogeneous ones?
To reduce the overall cost of software licensing and maintenance.
To ensure that a single vulnerability does not bypass all defense layers.
Heterogeneous controls prevent single points of failure. If all layers used the same technology, a single zero-day exploit could potentially compromise every layer simultaneously. Diversity ensures that an attacker must possess multiple, distinct exploits to traverse the various security layers, drastically increasing the difficulty for the adversary.
To simplify the process of configuring and managing security logs.
To minimize the need for external security audits and compliance checks.
Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?
It restricts lateral movement for an attacker who has compromised a device.
If a workstation is compromised, segmentation limits the attacker's ability to scan or connect to other network segments. By placing servers in a separate VLAN from end-user devices, the organization forces the attacker to find another way to move through the network, adding friction to the attack.
It allows for the implementation of zone-specific access control lists.
Segmentation provides the structure needed to apply granular access controls. You can enforce unique firewall rules for different zones based on business needs. This ensures that traffic between zones is inspected and verified, which is a classic implementation of a layered defense at the network level.
It eliminates the need for host-based firewalls on individual servers.
It facilitates better logging and monitoring of inter-zone traffic.
By routing traffic between zones through internal firewalls or gateways, organizations can gain visibility into traffic patterns that would otherwise be hidden. This improves detection capabilities, as abnormal traffic between segments can trigger alerts, serving as an early warning system within the layered defense architecture.
It automatically encrypts all data in transit between segments.
Which concept describes the use of security controls that operate at the perimeter, network, host, application, and data layers to protect an organization?
Zero Trust Architecture
Defense in Depth
Defense in depth is the systematic application of security controls across multiple layers, including perimeter, network, host, application, and data. This layered approach ensures that if a control at one layer fails or is bypassed, subsequent layers are in place to stop the attacker or limit damage.
Security Information and Event Management (SIEM)
Privileged Access Management (PAM)
Want more Defense in Depth practice?
Practice this domainAn enterprise network administrator needs to isolate a new public-facing web application so that a compromise of the web server does not immediately expose the internal corporate database and directory services. Which network architecture design pattern provides the most effective defense for this scenario?
Deploying the web server on the internal corporate VLAN alongside domain controllers to streamline administrative access and reduce network latency.
Implementing a flat network topology utilizing unmanaged switches to maximize throughput and simplify routing tables for incoming web traffic.
Configuring a demilitarized zone (DMZ) flanked by firewalls to separate public-facing web assets from internal network resources.
A demilitarized zone architecture establishes a dedicated buffered network segment protected by firewalls. This design ensures that traffic from the internet can only reach designated public services while strictly prohibiting direct connections from the perimeter into the trusted internal network.
Connecting the web server directly to the outer provider edge router via a public bridge to bypass internal switching bottlenecks.
A security engineer is designing a secure enterprise environment and needs to deploy network intrusion detection sensors to monitor east-west traffic moving between virtual machines inside an internal virtualization cluster. Which deployment method ensures the sensors successfully inspect internal segment traffic without introducing a single point of failure for packet forwarding?
Placing a dedicated physical inline bump-in-the-wire network intrusion prevention system between every internal virtual switch uplink.
Configuring hypervisor-level distributed virtual switches to mirror east-west traffic to dedicated virtual security monitoring appliances.
Hypervisor-level distributed switching capabilities can securely replicate internal virtual machine traffic patterns and send packet copies to virtualized sensor nodes. This out-of-band monitoring approach guarantees comprehensive visibility into east-west communications without risking packet drop or network downtime.
Routing all inter-VLAN traffic through a single legacy perimeter firewall using hardware router-on-a-stick configurations.
Disabling all stateful packet inspection on internal firewalls to allow maximum throughput for east-west virtualization traffic.
An organization is hardening its internal corporate network architecture to prevent unauthorized hosts from connecting to switch ports in common areas and conference rooms. Which TWO configurations should the network engineering team implement to achieve this security objective? (Choose TWO)
Enabling 802.1X port-based authentication integrated with a RADIUS server and extensible authentication protocol.
802.1X port-based authentication requires every connecting client to provide valid credentials to an authentication server before the switch port transitions to an active state. This robust mechanism prevents unauthorized physical devices from accessing the internal network environment.
Configuring static routing protocols on all access layer switches to bypass dynamic route poisoning attacks.
Configuring switch port security to restrict the maximum number of dynamically learned MAC addresses per interface.
Switch port security limits the quantity of unique MAC addresses allowed on a physical port. If an unauthorized device connects or if too many devices attach, the port immediately triggers a security violation action such as shutting down, thwarting unauthorized hardware.
Deploying unmanaged network hubs in conference rooms to simplify physical cable management and port density.
Disabling spanning tree protocol root guard on all core enterprise switches to accelerate topology convergence times.
During an internal network security audit, an engineer discovers that workstations on the human resources VLAN can directly communicate with sensitive database servers on the finance VLAN without passing through a filtering device. Which foundational architectural control is missing from this environment?
Deploying a high-availability server load balancer in front of the human resources workstation subnet.
Upgrading all edge routers to support Border Gateway Protocol with strict cryptographic route validation.
Enforcing inter-VLAN access control lists or deploying an internal firewall to inspect and restrict traffic between functional zones.
Inter-VLAN access control lists or internal firewalls enforce strict boundaries between separate network segments. Implementing this control ensures that traffic between the human resources VLAN and the finance VLAN is explicitly filtered according to the principle of least privilege.
Replacing all traditional dynamic host configuration protocol scopes with static IP address assignments.
A security architect is hardening an organization's network infrastructure against reconnaissance and layer-2 attacks. Which TWO actions should the engineering team take to mitigate common switch-based vulnerabilities? (Choose TWO)
Disabling dynamic trunking protocol on all user-facing access layer switch ports.
Dynamic trunking protocol allows switches to automatically negotiate trunk links with connected devices. Disabling this feature on user-facing access ports prevents malicious actors from injecting crafted DTP frames to force a port into a trunking state and bypass VLAN boundaries.
Enabling dynamic ARP inspection across all core routing interfaces without configuring DHCP snooping bindings.
Configuring the native VLAN on all trunk ports to use a dedicated, unused VLAN ID rather than the default VLAN 1.
Using default VLAN 1 as the native VLAN on trunk links leaves the network vulnerable to double-tagging VLAN hopping attacks. Changing the native VLAN to an isolated, non-functional ID ensures that injected frames cannot traverse unauthorized VLANs.
Routing all broadcast domain traffic through unmanaged Layer-1 repeating hubs to obscure physical topology.
Installing public-facing web servers directly into the native management VLAN of the core enterprise switches.
An enterprise network design utilizes an out-of-band management network for all core routers, firewalls, and switches. The management network is physically separated from the production data plane and uses dedicated management switches. What is the primary security advantage of this defensible architecture?
It completely eliminates the requirement to encrypt administrative SSH and HTTPS sessions across the network core.
It prevents compromised production workloads from launching lateral attacks against device management planes.
Physical separation ensures that even if an attacker completely compromises the production data plane, they cannot reach the management plane interfaces because there is no direct network path between the two distinct environments, protecting critical device controls.
It automatically accelerates routing convergence times across all enterprise boundary routers by removing administrative overhead.
It allows network operators to utilize unauthenticated cleartext telnet connections without risking confidentiality breaches.
Want more Defensible Network Architecture practice?
Practice this domainWhich password management practice best minimizes the impact of a credential stuffing attack?
Mandating password changes every 30 days
Requiring a minimum password length of 8 characters
Enforcing unique passwords per service
Unique passwords ensure that even if one account's credentials are breached in a data leak, the attacker cannot use those same credentials to access other platforms. This containment strategy isolates the impact of a breach and prevents the automated success typically associated with large-scale credential stuffing campaigns against modern web services.
Disabling account lockout after failed attempts
Which of the following describes the 'Principle of Least Privilege' in an access control context?
Granting all employees access to the root directory for troubleshooting
Providing users only the access required to complete their tasks
This definition aligns perfectly with the Principle of Least Privilege. By restricting access to only what is strictly necessary, an organization significantly reduces the impact of accidental mistakes, insider threats, and external attacks, as an attacker will find themselves limited by the restricted permissions of the compromised account.
Using the same shared password for all administrative accounts
Ensuring all users have administrator rights for software updates
What is the primary purpose of Salt in password hashing?
To shorten the length of the stored hash
To prevent the use of rainbow tables
Rainbow tables are pre-computed tables of hashes used to crack passwords quickly. By using a unique salt for every user, the set of possible hashes becomes effectively infinite for any given password, rendering rainbow tables useless because they cannot account for the random salt value injected into the hash function.
To increase the complexity of the user's password
To facilitate easier password recovery
A security administrator is reviewing the password policy for a high-security environment. The policy requires the use of a hardware token that generates a one-time password (OTP) based on a secret key and the current time. The administrator notices that some tokens are failing authentication because the server and tokens are not time-synchronized. Which of the following should the administrator implement to ensure the OTPs are validated correctly?
Enable NTP synchronization on the authentication server only.
Switch from time-based to event-based OTP tokens.
Increase the OTP length to 8 digits.
Configure a time drift window on the authentication server.
Time-based one-time password (TOTP) algorithms rely on synchronized clocks. If the token's clock drifts, the generated OTP will not match the server's expected value. Configuring a time drift window allows the server to accept OTPs from a few time steps before or after the current time, compensating for minor clock differences. This directly resolves the synchronization failures.
A security team is configuring password policies for a Windows Active Directory domain. They need to enforce a setting that prevents users from reusing any of their last 24 passwords. Which password policy setting should they configure?
Enforce password history
Enforce password history determines how many unique new passwords must be used before an old password can be reused. Setting it to 24 prevents reuse of the last 24 passwords, directly meeting the requirement. This is the correct setting because it specifically tracks and blocks previous password hashes, ensuring users cannot cycle back to recent passwords.
Minimum password age
Password must meet complexity requirements
Maximum password age
A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?
Credential stuffing
Pass-the-hash
Man-in-the-middle attack
A man-in-the-middle attack can intercept the authentication session and relay the one-time code in real time. If the attacker positions themselves between the user and the VPN, they can capture the password and the token code as the user submits them, then use them to authenticate before the code expires. This allows bypassing the hardware token requirement without possessing the physical token.
Brute-force attack
Want more Access Control and Password Management practice?
Practice this domainAn administrator needs to implement full disk encryption for a fleet of Windows workstations. Which algorithm provides the most robust security posture while maintaining hardware acceleration support in modern CPUs?
DES with CBC mode
Blowfish with ECB mode
AES-256 with XTS mode
AES-256 provides a significant security margin, and XTS is the standard mode designed specifically for block-oriented storage media. It prevents data manipulation attacks and provides high performance when combined with AES-NI hardware acceleration, making it the preferred choice for modern full disk encryption implementations across diverse hardware platforms.
RSA-4096 with OAEP
Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?
The RSA key length is insufficient for modern requirements
The private key will be stored without passphrase protection
The -nodes flag explicitly disables encryption of the generated private key. This means the key is saved in cleartext, creating a significant security risk where any user or process with read access to the file can steal the identity of the server without needing to provide a password.
The certificate will be self-signed and untrusted
The output file format defaults to a deprecated encoding
A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?
Lack of Perfect Forward Secrecy
Improper certificate chain verification
If the client code ignores certificate validation, it fails to verify the digital signature of the certificate against trusted Root CAs. This allows any attacker to issue a fraudulent certificate for the target domain, which the client will accept as valid, thereby facilitating a successful man-in-the-middle attack scenario.
Weak cipher suite negotiation
Use of outdated TLS 1.0 protocol
A developer is implementing an application that stores user passwords in a database. Which THREE of the following practices are essential for ensuring the cryptographic security of these stored secrets?
Using a unique, random salt for every user
Salting ensures that two users with the same password have different hashes stored in the database. This prevents attackers from using precomputed rainbow tables to crack multiple accounts simultaneously and forces them to perform a unique attack against each user, drastically increasing the time required for successful password recovery.
Using the Argon2id hashing algorithm
Argon2id is a memory-hard key derivation function that is specifically designed to be resistant to GPU and ASIC-based cracking attempts. Using a modern, slow algorithm like Argon2id is essential for current security, as it forces an attacker to dedicate significant memory and time per password guess attempt.
Storing passwords using SHA-256 with no salt
Applying a high iteration count (stretching)
Increasing the iteration count, or key stretching, adds computational cost to the hashing process. This makes brute-force attacks significantly slower, providing a massive barrier for attackers while remaining negligible for a legitimate user logging in once. It is a standard defense against high-speed hardware used in credential cracking.
Encrypting the database table with AES-128
An organization is migrating to a cloud environment and must ensure that data remains encrypted while in use by applications. Which technology should the security team implement to achieve this?
Transport Layer Security (TLS)
Full Disk Encryption (FDE)
Homomorphic Encryption
Homomorphic encryption allows mathematical operations to be performed directly on ciphertext. The result of the operation, when decrypted, matches the result that would have been obtained if the operations were performed on the original plaintext, providing a unique method for keeping data secure while it is being actively processed.
Database Transparent Data Encryption
A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?
Increase the RSA key size from 2048 to 4096 bits.
Require each update to be signed by a threshold of multiple independent keys.
Threshold signing requires a quorum of distinct private keys, often held in separate HSMs or by separate administrators, to produce one valid signature. An attacker who compromises a single key cannot meet the threshold, so forged updates fail verification. This directly addresses the goal of making single-key compromise insufficient, and it is supported by standards such as FIPS 186-5 and common HSM quorum configurations.
Publish the firmware hashes to a public transparency log.
Switch the signature algorithm from RSA to ECDSA with P-256.
Want more Cryptography practice?
Practice this domainRefer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?
The application will run normally because AppData is a standard location.
The application will be blocked from execution.
The JSON policy clearly specifies an action of 'Deny' for any file path matching the AppData directory pattern. Because the policy is in 'Enforce' mode, the security agent will block any attempt to execute a binary from this location, effectively stopping the user from running their application.
The application will run, but the activity will be logged for review.
The system will automatically move the application to Program Files.
Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?
Disabling local administrator accounts for standard users.
Implementing an application allowlisting solution.
Allowlisting works by creating a whitelist of authorized applications. Any file not on this list is blocked by the OS or agent. This effectively stops unauthorized software, scripts, and malware from running, providing a much stronger security posture than traditional antivirus, which relies on identifying known bad files.
Enabling real-time scanning in antivirus software.
Configuring the firewall to block all inbound traffic.
When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?
Applying the Principle of Least Privilege (PoLP) to user file shares.
Limiting user permissions ensures that if a workstation is compromised, the attacker can only encrypt the files that user has permission to modify. This prevents the ransomware from spreading to critical shared network drives or sensitive directories, effectively containing the potential impact of the infection to a single user's profile.
Disabling all network connections to the endpoint.
Utilizing offline or immutable backups.
Backups are the final line of defense against ransomware. Immutable backups cannot be modified or deleted by the ransomware, ensuring that data can be restored even if the primary systems are fully compromised. This allows organizations to recover without paying the ransom, neutralizing the attacker's primary leverage.
Deploying Endpoint Detection and Response (EDR) with behavioral blocking.
EDR agents monitor for ransomware behavior, such as rapid file renaming and entropy changes. By detecting these patterns in real-time, the agent can automatically kill the malicious process and isolate the host before the encryption process completes, providing a critical layer of automated response against novel malware variants.
Enabling guest access for easier file sharing across departments.
An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?
Scanning the hard drive for known malicious file signatures.
Analyzing the Master File Table (MFT) for deleted entries.
Performing a memory dump and analyzing it for anomalous process threads.
Memory forensics tools allow responders to examine the contents of RAM to find injected code, hidden processes, or tampered system calls. By comparing the memory state against a known-good baseline, analysts can identify the specific memory regions used by the file-less malware to maintain its stealthy presence.
Checking the Windows Event Logs for failed login attempts.
When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?
It improves the speed of system startup and file indexing.
It ensures that the computer cannot be booted from an external drive.
It requires authentication before the encryption keys are released to memory.
Pre-Boot Authentication forces the user to input a secret before the decryption keys are loaded into RAM. This ensures that the data is truly protected against cold-boot attacks and unauthorized access if the machine is powered off, as the drive remains encrypted until that specific challenge is successfully met.
It automatically syncs the encryption keys to a cloud-based backup.
A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?
Windows Defender Firewall with Advanced Security
BitLocker with TPM and PIN
AppLocker with default rules
Device Guard with Code Integrity policies
Device Guard (now part of Windows Defender Application Control) uses Code Integrity policies to enforce that only trusted, signed kernel-mode drivers and user-mode binaries can execute. It blocks unsigned or malicious drivers from loading, directly preventing rootkit installation. This is the correct choice because it specifically controls driver signing and integrity at the kernel level, meeting the requirement to allow only approved drivers.
Want more Endpoint Security practice?
Practice this domainYou are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?
Event ID 4624
Event ID 4672
This event explicitly indicates that a logon session has been assigned special privileges. It is the definitive audit log entry for identifying administrative access at the moment of login, providing a clear trail for security analysts monitoring for unauthorized privilege usage.
Event ID 4720
Event ID 1102
Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?
Only failure events are being audited
Both success and failure are being audited
The display lists 'Success and Failure' under the credential validation subcategory. This confirms that the security policy is set to log every authentication event, allowing for full visibility into legitimate login patterns and potential unauthorized access attempts targeting user credentials.
Auditing is completely disabled for this category
Only success events are being audited
Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?
Get-LocalGroupMember -Group Administrators
This cmdlet allows an auditor to list all members of the local Administrators group. Monitoring this group is vital, as attackers often add malicious accounts or elevated service accounts to maintain control over the compromised host during the post-exploitation phase.
Get-ScheduledTask
This command retrieves all scheduled tasks on the system. Attackers frequently use tasks to achieve persistence, executing malicious code at specific intervals or upon system startup, making this a high-priority area for auditing during a security incident response.
Get-Process -IncludeUserName
Get-Service | Where-Object {$_.Status -eq 'Running'}
Get-WinEvent -LogName Security
You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?
Set-ExecutionPolicy RemoteSigned
Set-ExecutionPolicy AllSigned
The AllSigned policy mandates that all scripts, including local ones, must be digitally signed by a trusted publisher. This is the recommended security posture for preventing unauthorized script execution and ensuring integrity, making it a critical hardening step for any secure environment.
Set-ExecutionPolicy Unrestricted
Set-ExecutionPolicy Bypass
Which Windows component is responsible for the centralized management of security configurations, including password policies and user rights, across a domain?
Windows Registry
Group Policy Objects
GPOs provide the primary mechanism for applying security policies and configurations across a domain. They allow for granular control and automated enforcement, ensuring that hardening standards are consistently applied to all managed workstations and servers in the environment.
Task Scheduler
Microsoft Management Console
Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?
Centralize logs to a SIEM for long-term storage
Centralizing logs is crucial because local logs can be cleared by an attacker to hide their tracks. A SIEM ensures that logs are stored securely off-host, allowing for correlation and analysis that would be impossible if limited only to local disk space.
Increase maximum log size to prevent log overwriting
Increasing the size of security logs ensures that events remain on the machine for a longer duration, reducing the chance of critical evidence being overwritten during an incident. This provides a larger forensic window for incident responders to reconstruct the attack timeline.
Audit every single file access on the system
Enable auditing of process creation and logons
Monitoring process creation and logons is vital for detecting suspicious activity. Process auditing helps identify malicious execution, while logon auditing tracks authentication patterns, both of which are high-value telemetry points for detecting lateral movement and privilege escalation in a network.
Require domain admins to clear logs daily
Want more Windows Automation and Auditing practice?
Practice this domainA security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?
TCP connection state tables showing persistent half-open sessions on port 53.
Unusually high frequency and elevated entropy levels within TXT or subdomain record queries.
Malicious actors encode stolen data or remote commands within the subdomains of DNS requests or inside TXT records. Inspecting query frequency, length, and entropy reveals the high-density encoded payloads characteristic of modern tunneling tools like Iodine.क्क
Frequent receipt of ICMP Destination Unreachable messages indicating blocked UDP traffic.
Elevated round-trip time latency on standard HTTP GET requests traversing proxy servers.
An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?
Implementing Port Security along with Static ARP entries on all critical endpoints.
Enabling BPDU Guard and Root Guard on all designated edge access ports.
Deploying Dynamic ARP Inspection paired with an active DHCP Snooping binding table.
DHCP Snooping tracks legitimate IP-to-MAC address assignments by monitoring untrusted switch ports. Dynamic ARP Inspection references this verified database to intercept and drop malicious ARP packets, successfully preventing both DHCP spoofing and man-in-the-middle ARP cache poisoning attempts.क्क
Configuring VLAN Access Control Lists alongside private VLAN isolated port modes.
During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?
Enabling remote attackers to execute arbitrary shell commands via buffer overflows in the ICMP daemon.
Allowing unauthorized entities to gather precise system uptime and clock synchronization data.
ICMP Timestamp replies expose a device's current clock and uptime, letting an attacker fingerprint the OS, infer patch cycles, and correlate hosts across the estate. On perimeter routers this reconnaissance data aids targeted exploitation, which is the specific risk the question asks about.
Exposing internal private IP address ranges through embedded DNS zone transfer responses.
Facilitating high-bandwidth distributed denial-of-service reflection attacks using small spoofed packets.
During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?
Deploying a traditional static packet-filtering firewall with inbound rule sets.
Enforcing strict Egress Filtering policies on internal router and firewall interfaces.
Egress filtering inspects and blocks outbound traffic at router and firewall interfaces, permitting only approved ports and protocols. This directly prevents the unexpected outbound administrative channels observed, satisfying the requirement to restrict unauthorised outbound communication at the network perimeter.
Configuring port security on all access layer switch ports to limit MAC addresses.
Implementing WPA3 Enterprise wireless security across all corporate access points.
An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?
The workstation is performing a standard DNS resolution process.
The system is initiating a legitimate peer-to-peer file transfer.
The host is performing TCP half-open reconnaissance.
TCP half-open scanning, often called SYN scanning, involves sending SYN packets to probe ports. The attacker analyzes the responses to determine if ports are open, closed, or filtered. Because the full handshake is never completed, the scanning activity is harder to log on the target system.
The network interface is experiencing a broadcast storm.
A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?
Telnet
IPsec
IPsec offers a suite of protocols that provide encryption, integrity, and authentication at the network layer. By securing packets between two hosts, it ensures that even if internal traffic is intercepted, the payload remains unreadable and protected from tampering, which is necessary for sensitive data transmission.
HTTP
SNMPv1
Want more Networking and Protocols practice?
Practice this domainA security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?
chmod 777 cleanup.sh
chmod 755 cleanup.sh
chmod 700 cleanup.sh
The 700 octal mode provides full control to the owner (rwx) and explicitly denies all access to group and other users. This ensures that only the file owner can interact with the script, effectively mitigating risks associated with unauthorized execution or inspection of sensitive administrative tasks on the Linux system.
chmod 600 cleanup.sh
Refer to the exhibit. A user attempts to delete a file located inside '/opt/backup', but the operation fails with a 'Permission denied' error. Given the directory permissions shown, what is the most likely cause?
The user lacks the execute permission on the /opt/backup directory.
The user lacks write permission on the /opt/backup directory.
Deleting a file requires the write permission on the parent directory because it involves removing a directory entry. The 'r-x' permissions for others demonstrate that the user does not have write access, which is the mandatory requirement for modifying the contents of a directory, including file deletion.
The file inside the directory is owned by root and is immutable.
The user does not have the 'sudo' command available in their path.
An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?
tail -f /var/log/auth.log
The '-f' flag tells the tail utility to follow the file, meaning it will continuously display new lines as they are appended to the log. This is the industry-standard method for live log monitoring and immediate detection of authentication failures, such as repeated SSH login attempts or brute-force attacks.
head -n 20 /var/log/auth.log
less +F /var/log/auth.log
The '+F' option in the less pager puts the utility into a mode similar to 'tail -f', monitoring for new additions. This is highly effective because it allows the user to press Ctrl+C to pause the stream, search through history, and then resume monitoring without restarting the command.
cat /var/log/auth.log | grep -v 'accepted'
more /var/log/auth.log
A Linux administrator needs to identify which processes are currently consuming the most CPU resources. Which command provides an interactive, real-time view of system performance and process activity?
ps aux
top
The top command provides an interactive, live dashboard of system activity. It updates at regular intervals, showing the most resource-intensive processes. This allows administrators to sort by CPU usage, identify abnormal spikes, and manage processes, which is essential for diagnosing performance issues or detecting malicious background tasks.
ls -l /proc
df -h
A security analyst needs to determine which network ports are currently listening for incoming connections on a Linux server. Which command is best suited for this task?
ss -tulpn
The ss command with these flags displays all TCP and UDP listening ports, along with the numeric service port and the process ID (PID) that opened the port. This level of detail is vital for security professionals to map open network sockets back to specific running applications.
ifconfig -a
ping -c 5 localhost
dig @localhost
A security analyst is reviewing a compromised Linux web server. The attacker escalated to root and then ran a script that unlinked the file /var/log/auth.log to hide their tracks. The analyst runs `lsof | grep auth.log` and sees the file is still open by the rsyslogd process, but `ls /var/log/auth.log` reports that the file does not exist. Which of the following best explains why the file content is still accessible through the open file descriptor?
The Linux kernel maintains the inode and data blocks until the last open file descriptor referencing the inode is closed, even after the directory entry is removed.
On Linux, unlinking a file only removes the directory entry (the name-to-inode link). The inode's link count drops, but the inode and its data blocks are not reclaimed while any process still holds an open file descriptor. The analyst can recover the content through /proc/<pid>/fd/<n>, which is why the data remains accessible to rsyslogd until it is restarted or closes the descriptor.
The rsyslogd process has the file memory-mapped with mmap, so the page cache keeps a copy that ls can still resolve by inode lookup.
The file was moved to a hidden directory by the attacker, and lsof is resolving the path from the process's current working directory rather than the real inode.
The ext4 filesystem journals file deletions, and lsof reads the journal to reconstruct the file contents until the journal is overwritten by subsequent writes.
Want more Linux Fundamentals practice?
Practice this domainAn analyst notices that the SIEM is triggering an excessive number of 'False Positive' alerts related to failed login attempts. Which strategy is most effective for reducing these alerts without compromising security posture?
Disable all failed login logging on domain controllers to save SIEM storage.
Increase the severity level of all login failure logs to 'Critical'.
Implement a threshold-based correlation rule to alert only after five failed attempts within one minute.
Threshold-based alerting filters out transient, single-instance failures caused by mistyped passwords or minor sync issues. By requiring multiple failures in a short duration, the system ignores common user errors while still catching automated brute-force attacks, successfully balancing signal fidelity with the need for continuous security monitoring and oversight.
Archive all failed login logs to cold storage immediately upon ingestion.
Refer to the exhibit. An analyst observes the provided log output. What is the most likely security incident occurring, and what is the best immediate action?
Hardware failure; replace the server network interface card immediately.
Brute-force attack; investigate the source IP and block it if unauthorized.
The rapid cadence of failed attempts from a single source strongly suggests an automated brute-force attack. Investigating the source IP allows the analyst to verify if the machine is a known asset or an unauthorized intruder, and blocking it is the correct containment strategy to protect the server.
Network congestion; increase the logging frequency of the server.
User error; reset the user's password to clear the event logs.
Which THREE of the following represent critical log sources that should be ingested into a SIEM for effective network-wide security visibility? (Choose three)
Firewall logs
Firewall logs document allowed and denied traffic at network boundaries. They are essential for identifying reconnaissance, data exfiltration, and communication with known malicious command-and-control servers. Analyzing these logs helps security teams understand how traffic flows through the perimeter and identify potential entry points for attackers or internal threats.
Local printer spooler temporary files
Authentication (Active Directory) logs
Active Directory logs provide a detailed history of user logins, privilege changes, and group membership updates. These are critical for detecting credential theft, account hijacking, and insider threats. Monitoring authentication flows is mandatory for identifying how an attacker establishes a foothold and moves laterally throughout the Windows domain environment.
Antivirus/EDR alerts
EDR alerts document malicious files, process injections, and suspicious script executions on hosts. These logs are vital for confirming that an attack has successfully bypassed perimeter defenses. Ingesting these alerts into a SIEM provides the context needed to link host-based malicious behavior with network-based communication, enabling complete incident investigation.
Office document metadata templates
A security analyst is tuning the SIEM to reduce noise. The current rule fires whenever a Windows event with ID 4625 (failed logon) occurs. Which modification should the analyst make to the rule to better identify a brute-force attack while reducing false positives?
Set the rule to alert only when event ID 4625 occurs outside of business hours.
Add a filter to exclude all failed logon events from privileged accounts.
Configure the rule to trigger only when event ID 4625 is followed by event ID 4624 (successful logon) from the same user within 1 minute.
Change the rule to trigger only when the same source IP generates more than 10 failed logons within 5 minutes.
Threshold-based correlation on source IP and time window is a standard SIEM technique to distinguish brute-force attempts from isolated user errors. Ten failures in five minutes from one source exceeds normal human error rates and indicates automated guessing, while ignoring scattered single failures that are typical of mistyped passwords.
A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?
Alert when any host initiates a connection to a country that is not on an approved list.
Correlate outbound traffic volume with destination IP reputation and unusual port usage, and alert on deviations from the host's historical baseline.
This strategy combines multiple weak indicators (volume, destination reputation, port) and behavioral baselining to increase confidence. Exfiltration often involves transfers to unknown or low-reputation IPs on non-standard ports, and volume that is anomalous for that specific host. Correlating these factors reduces false positives and catches stealthy exfiltration that avoids simple thresholds.
Alert when any internal host sends more than 1 GB of data to an external IP address within an hour.
Monitor for DNS queries to known command-and-control domains and alert on any match.
A security analyst is tuning a Splunk Enterprise correlation search that detects brute-force attempts against SSH. The current search fires thousands of alerts daily because it counts every failed password event, including those from a single user who mistypes a password once. The analyst needs to reduce noise while still catching distributed brute-force attacks. Which modification should the analyst make to the correlation search?
Add a threshold condition that triggers only when more than 10 failed logins occur from the same source IP within 5 minutes.
Correlate failed logins across multiple source IPs by counting distinct source IPs per target account over a longer window, and trigger when the distinct count exceeds a threshold.
This approach directly addresses distributed brute-force attacks, where many source IPs each try a few passwords against the same account. By counting distinct source IPs per target account over a longer window, the search detects the attack pattern while ignoring isolated mistyped passwords from a single user. It reduces false positives because a single user typically fails from one or two IPs, not many, and it still catches the distributed behavior.
Increase the search time window to 24 hours and lower the alert threshold to 5 failed logins per user.
Filter out all failed password events for service accounts and only alert on failed logins for interactive user accounts.
Want more Log Management and SIEM practice?
Practice this domainYour organization is adopting the CIS Critical Security Controls to bolster defense. You are currently focused on establishing a secure baseline configuration for all workstation images. Which specific CIS Control should you prioritize to ensure that unauthorized software and unauthorized configuration changes are mitigated?
CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 2: Data Protection
CIS Control 4: Secure Configuration of Enterprise Assets and Software
Control 4 specifically requires the establishment and maintenance of secure configurations for all enterprise assets. It ensures that systems are deployed with hardened settings, unnecessary ports are closed, and only authorized software is permitted. This effectively mitigates the risk of exploitation through default settings or unauthorized application execution.
CIS Control 8: Audit Log Management
An organization is performing a gap analysis against the CIS Controls. They find that while they have strong identity management, they fail to track the software installed on local machines, leading to 'shadow IT.' Which CIS Control should they implement to address this specific visibility gap?
CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 2: Inventory and Control of Software Assets
Control 2 requires maintaining an up-to-date inventory of all software installed on enterprise assets. This ensures that unauthorized software (shadow IT) can be detected and managed. By enforcing this control, security teams gain the visibility needed to authorize or remove applications, closing the gap described in the scenario.
CIS Control 3: Data Protection
CIS Control 7: Continuous Vulnerability Management
An organization is reviewing CIS Control 11: Data Recovery. Which of the following activities best demonstrates adherence to the 'testing' requirement of this control?
Running a full system backup every night at 2:00 AM.
Storing all backup tapes in an off-site, climate-controlled facility.
Conducting a periodic, documented restore process to verify data integrity.
Performing a documented, periodic restore test is the core requirement for Control 11. It proves that the backup system is working as intended, data is not corrupted, and the team knows the necessary steps to recover critical business systems within the required recovery time objectives after an incident.
Encrypting all backup media to prevent unauthorized access.
An organization is applying CIS Control 9: Email and Web Browser Protections. They have successfully implemented domain-based message authentication (DMARC). What is the primary security goal being achieved by this implementation?
Encryption of email traffic between mail servers.
Prevention of unauthorized use of the organization's domain for spoofing.
DMARC specifically enables domain owners to protect their domain from being used for email spoofing. It provides a feedback mechanism and policy enforcement that tells receiving mail servers how to reject or quarantine emails that do not pass SPF or DKIM authentication, directly preventing domain impersonation and phishing.
Hardening web browser settings to prevent XSS attacks.
Scanning of inbound email attachments for malware signatures.
A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?
Adopt the CIS Risk Assessment Method (CIS RAM) to identify, analyze, and prioritize risks based on the CIS Controls.
CIS RAM is a prescriptive risk assessment method designed to help organizations implement the CIS Controls by identifying and prioritizing risks. It provides a structured approach to measure security posture and make informed decisions about resource allocation, directly supporting the CISO's goal of tracking effectiveness and prioritizing improvements.
Conduct a penetration test to identify vulnerabilities in the organization's external-facing infrastructure.
Deploy a SIEM solution to collect and correlate security events from all network devices.
Implement the NIST Cybersecurity Framework to map current activities to the five core functions.
A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?
Implement a phishing simulation program with regular campaigns, provide immediate feedback to users who click, and track improvement over time.
This approach aligns with CIS Control 14 by providing continuous, practical training through simulated phishing attacks. Immediate feedback educates users in the moment, and tracking improvement measures the program's effectiveness. It goes beyond mere completion tracking to actively reduce susceptibility by reinforcing secure behavior and adapting training based on results.
Require employees to complete a computer-based training module on phishing once per quarter and pass a quiz.
Send monthly security newsletters to all staff highlighting recent phishing trends and best practices.
Conduct annual security awareness training for all employees and track completion rates.
Want more Security Frameworks and CIS Controls practice?
Practice this domainAn enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?
Store cloud provider credentials in base64-encoded Kubernetes Secret objects and mount them as environment variables.
Configure cluster-wide IAM roles on the underlying worker nodes and allow all hosted pods to inherit administrative permissions.
Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.
Projected service account tokens provide automatically rotated, cryptographically signed tokens with strict audience limitations. This ensures that even if a token is exfiltrated, its lifespan is extremely short and its usability is strictly bounded to intended APIs.
Embed the static cloud API keys directly into the container base image layers to ensure consistency across deployments.
A security engineer wants to ensure that container images are not modified after they are built and pushed to a registry. Which mechanism provides the strongest assurance of image integrity and authenticity?
Implementing a read-only filesystem for the container at runtime.
Using SHA-256 image digests instead of mutable image tags.
Applying cryptographic digital signatures to container images.
Digital signatures provide a verifiable link between the image and the build process. By using a private key to sign the image manifest, the organization ensures that any subsequent modifications to the image data will cause the signature validation check to fail upon deployment.
Scanning images for known vulnerabilities using a static analyzer.
When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?
Disable all kernel modules on the host operating system.
Use a specialized container runtime like gVisor to intercept system calls.
gVisor acts as a user-space kernel that intercepts and handles system calls. By limiting the number of system calls that reach the host kernel, it drastically reduces the available attack surface for privilege escalation and kernel exploits, effectively containing the potential damage from a compromised application within the guest.
Increase the memory limit for every container in the cluster.
Run all containers with the --privileged flag to ensure compatibility.
Which of the following is the most effective way to prevent secrets (such as API keys) from being leaked via container images?
Encrypt the Dockerfile using a secret key before building.
Use orchestrator-native secret management to inject secrets at runtime.
Runtime injection ensures that secrets reside only in the memory of the container and are not persisted in the image layers. This prevents secrets from being exposed through registry access or image analysis, allowing for easier rotation and centralized auditing of secret usage within the containerized application environment.
Delete the secrets in a subsequent RUN layer during the build.
Set the file permissions on the secret to 600 after copying it.
Refer to the exhibit. What is the security impact of the provided Kubernetes security context configuration?
The pod will be unable to pull the image from the registry.
The container is protected against setuid-based privilege escalation.
By setting 'allowPrivilegeEscalation' to false, the container runtime prevents the process from gaining more privileges than its parent. This effectively neutralizes setuid binaries that could otherwise be leveraged by an attacker to elevate their privileges from a standard user to root within the container's isolated execution environment.
The pod will block all network traffic from the container.
The application will automatically have its vulnerabilities patched.
A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?
Enable the NodeRestriction admission plugin and rotate the kubelet client certificates on all worker nodes.
Add a seccomp profile of RuntimeDefault to the pod and set allowPrivilegeEscalation to false in its securityContext.
Create an OPA Gatekeeper constraint that denies pods whose namespaces carry the privileged enforcement label.
Remove the privileged label from the tenants namespace so the restricted profile is enforced there, and refactor the legacy job to run without a hostPath mount.
The hostPath volume is what exposes the node's kubelet directory to the pod, and the namespace's privileged enforcement label is what allowed that volume to be admitted despite the cluster-wide restricted profile. Restoring restricted enforcement blocks hostPath volumes entirely and forces the legacy job to be reworked, directly removing the pod's ability to read node files. The other options leave the mount or the permissive label in place.
Want more Container Security practice?
Practice this domainRefer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?
Reboot the workstation immediately
Isolate the workstation from the network
Isolating the host prevents the attacker from issuing further commands or exfiltrating data, effectively containing the threat. By cutting the network path, you stop the malicious script from reaching its destination without destroying the volatile memory evidence needed to identify the full scope of the attack activity.
Delete the PowerShell process
Update the antivirus definitions
An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?
Integration with the social media monitoring platform
Integration with external threat intelligence feeds
Pre-defined and validated response playbooks
Automated response tools rely on playbooks to determine actions. If these are not pre-defined and tested, the tool could inadvertently disrupt business operations. Validated playbooks ensure the automation performs safe and effective containment actions without requiring manual intervention, which is essential during a fast-moving, high-severity security incident.
Unlimited cloud storage for log retention
During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?
Resetting compromised user passwords
If an attacker has stolen credentials, simply removing the backdoor is insufficient because the attacker can still authenticate using the compromised account. Resetting passwords is a mandatory eradication step to prevent the adversary from regaining access via legitimate authentication channels after the malicious artifacts are removed.
Analyzing the memory dump for malware signatures
Patching the vulnerability used for initial access
Eradication must address the root cause of the incident. If the vulnerability that allowed the initial entry remains unpatched, the attacker or others will simply re-exploit it. Patching ensures the environment is hardened, preventing the attacker from re-entering through the same path that was used during the compromise.
Re-imaging infected systems from a known-good source
Re-imaging is the most reliable way to remove sophisticated malware that may have hidden itself deep within the operating system. Because attackers can modify system files and kernel drivers, simple file deletion is often ineffective, making re-imaging from a trusted source the best way to ensure complete eradication.
Drafting an incident report for executive leadership
Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?
SQL Injection; Containment
Cross-Site Scripting; Identification
The log displays an XSS payload injected into a form field, which the framework correctly blocked. This activity represents an active probe by an attacker. It must move to the Identification phase to determine the extent of the scanning or exploitation attempts being conducted against the web application.
Cross-Site Request Forgery; Eradication
Buffer Overflow; Preparation
Which document is essential to have in place before an incident occurs to ensure legal and regulatory compliance regarding data privacy and breach notification?
The Incident Response Plan
The Incident Response Plan is the primary document that outlines the steps to take during a breach, including legal and regulatory notification requirements. Having this plan in place ensures that legal obligations are met promptly, reducing the risk of non-compliance penalties and ensuring consistent communication with regulatory authorities.
A list of all employee hardware serial numbers
The corporate employee handbook
The server room floor plan
An analyst receives an alert that a server's CPU usage has spiked to 100% and is generating outbound traffic to a known command-and-control IP address. The server is critical for a production application. After confirming the compromise, the analyst decides to isolate the server from the network. Which incident response phase does this action fall under?
Containment
Containment aims to limit the scope and impact of an incident. Isolating the server prevents further lateral movement and stops the attacker from exfiltrating data or causing more damage. This is a classic containment action, as it separates the affected system from the rest of the network while allowing forensic analysis to continue.
Preparation
Recovery
Eradication
Want more Incident Handling and Response practice?
Practice this domainA system administrator needs to harden a public-facing Linux server against automated brute-force attacks. Which configuration change in the /etc/ssh/sshd_config file provides the most significant reduction in the attack surface regarding credential stuffing?
PermitRootLogin no
PasswordAuthentication no
Disabling password authentication forces the use of cryptographic keys, which are significantly harder to brute-force than even complex passwords. This change effectively eliminates the risk of automated credential stuffing because the server will reject any attempt that does not present a valid private key, regardless of the password's strength.
MaxAuthTries 3
AllowUsers admin
An information security auditor discovers a custom compiled binary in a shared directory with the following permissions: -rwsr-xr-x. The file is owned by the root user. What is the primary security implication of this finding?
The file can be modified by any user in the group.
The binary executes with the privileges of the root user.
The 's' in the owner's execute position indicates the Set User ID bit is active. Since the owner is root, any user running this binary will have their effective user ID changed to root. This allows the program to perform administrative tasks that the standard user would normally be restricted from.
The file is encrypted and requires a password to run.
The binary is restricted to running only in runlevel 1.
To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?
Setting a BIOS/UEFI password
A BIOS or UEFI password prevents unauthorized users from changing the boot order or modifying hardware-level settings. This is the first line of defense against an attacker trying to boot the system from an external USB drive or optical media to gain access to the underlying data on the disks.
Configuring a GRUB bootloader password
Password protecting the GRUB bootloader prevents unauthorized users from modifying boot parameters, such as adding 'init=/bin/sh' to gain a root shell. This control ensures that even if someone can see the boot menu, they cannot interfere with the kernel's startup process or enter restricted maintenance modes.
Enabling the sticky bit on /tmp
Disabling the IPv6 network stack
Implementing Full Disk Encryption (FDE)
Full Disk Encryption ensures that the data remains inaccessible even if the physical hard drive is removed or the system is booted into a different operating system. It requires a passphrase or hardware token to unlock the volume during the early stages of boot, providing robust protection for sensitive data.
A security administrator needs to block all incoming traffic to a server except for SSH (port 22) using the nftables framework. Which configuration approach best follows the principle of least privilege?
Create a rule to allow port 22 and log all other traffic.
Add a rule at the end of the chain that rejects all TCP traffic.
Set the default policy of the INPUT chain to ACCEPT.
Set the default policy to DROP and add an allow rule for port 22.
This approach implements a 'whitelist' strategy, which is the most secure method for firewall configuration. By dropping all traffic by default, the administrator ensures that only the traffic explicitly defined (in this case, SSH) can reach the server, effectively closing all other ports and reducing the attack surface.
A security engineer is configuring a Linux server to enforce password quality for all local accounts. The requirement is that passwords must be at least 14 characters long, contain at least one uppercase letter, one lowercase letter, one digit, and one special character, and must not repeat any of the last 5 passwords. Which file should the engineer edit to enforce these settings?
/etc/pam.d/login
/etc/login.defs
/etc/security/pwquality.conf
The /etc/security/pwquality.conf file is used by the pam_pwquality PAM module to enforce password complexity requirements such as minimum length (minlen), required character classes (ucredit, lcredit, dcredit, ocredit), and password history via the remember parameter (often set in PAM configuration but also influenced by pwquality). This is the correct location to define the specified password policy for local accounts on modern Linux distributions.
/etc/shadow
A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?
Remove the 'noexec' option from /tmp and /var/tmp so the developer can move scripts there and execute them, keeping /home locked down.
Add the 'nosuid' option to /home only, because nosuid prevents all executable files from running and resolves the developer's concern.
Remount /home with the 'noexec' option and require the developer to store and execute scripts from /var/tmp instead.
Leave /home mounted without 'noexec' and instead enforce execution control through SELinux booleans or AppArmor profiles that restrict which binaries the scheduled process may run.
When legitimate scripts must execute from /home, using mandatory access control such as SELinux booleans or AppArmor profiles restricts execution to approved binaries and paths without breaking the developer's workflow. This maintains defense in depth while allowing required functionality, unlike blunt mount options that would block all execution.
Want more Linux Security and Hardening practice?
Practice this domainA system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?
User Account Control (UAC)
BitLocker Drive Encryption
Share Permissions
Share permissions act as the first gatekeeper for network resources. If the Share permission is set to 'Deny' or does not include the user, they cannot access the contents regardless of their NTFS permissions. Both layers must permit access for the user to view or modify files.
Group Policy Object (GPO) Inheritance
Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?
Files and subfolders inherit the permissions from the parent.
Object Inherit (OI) ensures files inherit the ACE, and Container Inherit (CI) ensures subfolders inherit the ACE. These flags are critical for administrative efficiency, as they automatically propagate security settings to all child objects, ensuring consistent application of the least privilege principle throughout the file hierarchy.
Only existing files are modified.
The permissions are applied to C:\Data only, not children.
The user cannot delete the folder.
Which Windows feature allows for fine-grained access control based on user attributes like department or project code rather than just security groups?
Access-Based Enumeration (ABE)
Dynamic Access Control (DAC)
DAC uses claims-based identity and resource properties to enforce access. It allows for complex rules, such as 'only managers in the Finance department can access files marked as sensitive,' which is far more efficient than managing membership in dozens of static security groups across the domain.
NTFS Permissions
User Account Control (UAC)
A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?
The 'Deny' permission only applies if Elena is directly listed, not via group membership.
The 'Write' permission is not included in the 'Modify' permission, so the Deny for Write does not affect Modify.
The 'Deny' permission for the 'Contractors' group takes precedence over the 'Allow' permission inherited from 'Project_X'.
In Windows access control, explicit Deny entries in an ACL override any Allow permissions, whether inherited or explicit. Because Elena is a member of 'Contractors', the Deny for Write applies directly to her, blocking the Modify permission from 'Project_X'. This is by design to ensure security restrictions are enforced.
The 'Modify' permission from 'Project_X' is inherited and therefore is overridden by the explicit 'Deny'.
A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?
The 'Sales' group has an explicit 'Deny' for 'Delete' that overrides the 'Full Control' from 'Managers'.
If the Sales group has an explicit Deny for Delete, that Deny takes precedence over the Allow from Managers. Even though Bob is a Manager with Full Control, the Deny from Sales membership blocks deletion. This is a classic case of Deny overriding Allow, and it explains why Bob cannot delete files despite having Full Control via another group.
The 'Full Control' permission from 'Managers' does not include the 'Delete' permission.
Bob's user account has an explicit 'Deny' for 'Delete' that is inherited from the parent folder.
The 'Read & Execute' permission from 'Sales' is more restrictive and overrides the 'Full Control' from 'Managers'.
A security analyst is investigating a Windows Server 2019 file server where a user named Alice reports she cannot open a file in a shared folder even though she is a member of a group that has 'Modify' permission on that file. The analyst runs 'icacls' and sees that Alice's user account has an explicit 'Deny' entry for 'Read & execute' on the file. What is the most likely reason Alice cannot access the file?
Explicit Deny permissions take precedence over any Allow permissions, including those inherited from group membership.
In Windows ACL evaluation, an explicit Deny ACE is evaluated before any Allow ACE, regardless of whether the Allow comes from group membership or inheritance. Because Alice's user account has a direct Deny on 'Read & execute', that deny overrides the Modify permission granted to her group, preventing her from opening the file. This is a fundamental rule of Windows access control.
The file's Share permissions are more restrictive than its NTFS permissions, preventing access.
Alice's group membership has not been refreshed in her current logon token, so the Modify permission is not applied.
The 'Modify' permission assigned to Alice's group is inherited from a parent folder and is therefore ignored.
Want more Windows Access Controls practice?
Practice this domainAn organization is migrating to a hybrid cloud environment. Which security control is most effective for preventing unauthorized lateral movement between virtual machines residing on the same physical hypervisor?
Deploying a Network Intrusion Detection System (NIDS) at the virtual switch level.
Implementing a traditional hardware-based firewall at the edge of the datacenter.
Utilizing micro-segmentation policies via distributed firewalls.
Distributed firewalls operate at the virtual NIC level, enabling granular security policies that follow the VM regardless of host migration. This effectively isolates workloads from each other, preventing lateral movement even if the attacker has gained local access, which is fundamental to zero-trust cloud security models.
Enforcing full disk encryption on all virtual hard drives.
A security engineer is configuring a new AWS S3 bucket to store sensitive PII. Which combination of settings best adheres to the principle of least privilege for the bucket policy?
Enable public access and rely on bucket ACLs for granular object permission.
Restrict access to specific IAM roles and require Secure Transport.
Restricting access to specific IAM roles ensures that only authorized entities can interact with the bucket. Requiring Secure Transport (HTTPS) ensures that data in transit is encrypted, protecting against interception. This combination adheres to the principle of least privilege and robust data protection standards.
Assign full administrative rights to the bucket root user for ease of management.
Use a wildcard principal in the bucket policy to allow internal cross-account access.
Which TWO of the following practices are recommended to mitigate the risk of 'Model Inversion' attacks in an AI/ML deployment?
Apply differential privacy noise to the training dataset.
Adding statistical noise to the training data ensures that the model learns general patterns rather than memorizing specific, sensitive individual data points. This mathematical approach significantly reduces the accuracy with which an attacker can reconstruct the original training records from model outputs.
Increase the confidence interval thresholds in the model API output.
Restrict the level of detail provided in API response predictions.
Limiting the output, such as removing detailed confidence scores or raw probability distributions, makes it much harder for attackers to conduct inversion attacks. By providing only the final classification rather than granular data, the surface area for reconstructing training inputs is greatly reduced.
Implement multi-factor authentication for all API management endpoints.
Regularly rotate the API keys used to access the inference model.
Which virtualization security concern occurs when an attacker breaks out of the guest operating system to interact directly with the hypervisor?
Resource exhaustion.
Virtual Machine escape.
A VM escape allows an attacker to bypass the isolation provided by the hypervisor and interact with the host OS. This is a severe security vulnerability that compromises the entire virtualization environment, potentially leading to unauthorized data access and total control over all virtualized assets on that host.
Snapshot tampering.
Hypervisor misconfiguration.
Which cloud security concept describes the automation of infrastructure deployment using code templates to ensure a consistent, secure, and repeatable environment?
Container Orchestration.
Infrastructure as Code.
Infrastructure as Code (IaC) uses machine-readable definition files to automate the deployment of cloud infrastructure. This ensures that security best practices, such as encryption and access control, are baked into the templates, creating a consistent and repeatable security posture across the entire organization.
Serverless Computing.
Hyper-converged Infrastructure.
A financial services company runs sensitive workloads on a Type 1 hypervisor. The security team wants to detect if a guest VM attempts to escape and directly access the hypervisor's memory. Which virtualization-specific security control should they implement?
Host-based intrusion detection system (HIDS) on each guest
Virtual firewall
Hypervisor introspection
Hypervisor introspection allows the hypervisor to monitor and analyze the memory and state of guest VMs from outside the guest, enabling detection of malicious activity such as escape attempts. It operates at the hypervisor layer, providing visibility that traditional in-guest agents cannot achieve, and is specifically designed to identify anomalies like unauthorized memory access from a guest to the hypervisor.
Security information and event management (SIEM) correlation
Want more Virtualization, Cloud, and AI Essentials practice?
Practice this domainA security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?
nmap -sU
nmap -sA
nmap -sS
nmap -sT
The -sT option performs a TCP connect scan using the operating system's connect() system call, which does not require raw socket privileges. This makes it ideal when running Nmap as a non-root user or when the analyst lacks the ability to send raw packets. It completes the full TCP three-way handshake against each target port.
A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?
OpenVAS (Greenbone Vulnerability Management)
OpenVAS, now delivered through Greenbone Vulnerability Management, is an open-source vulnerability scanner with a continuously updated feed and support for both authenticated and unauthenticated scans. It has no per-host licensing limit, making it suitable for scanning a 254-host subnet at no cost while still meeting the maintenance and capability requirements.
Nessus Essentials
Nmap with the NSE vuln category
Wireshark
During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?
Perform a TCP SYN scan of the internal subnet from the compromised host
Run a credentialed vulnerability scan from the scanner appliance using domain admin credentials
Capture traffic with tcpdump on the compromised host for several hours
Upload and execute a local enumeration script such as WinPEAS or Seatbelt
Local enumeration tools like WinPEAS and Seatbelt run from the compromised host and collect patch levels, missing updates, weak service permissions, saved credentials, and misconfigurations that remote scans often miss. Because the tester already has a shell, this approach directly answers the goal of finding local vulnerabilities without needing additional credentials or scanner access.
A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)
Kerberos ticket for domain authentication
SSH credentials for Linux hosts
Nessus uses SSH credentials to log into Linux and Unix hosts and run local commands for patch level, configuration, and vulnerability checks. Without valid SSH credentials, the scan falls back to unauthenticated checks, which are less accurate. Configuring SSH credentials is essential for authenticated scanning of Linux systems in a mixed environment.
Database credentials for SQL Server instances
SNMP community strings for network devices
SMB credentials for Windows hosts
For Windows targets, Nessus uses SMB credentials to authenticate and perform local checks via remote registry, file system access, and WMI queries. Providing SMB credentials enables Nessus to detect missing patches, insecure configurations, and other host-based vulnerabilities that are invisible to unauthenticated scans. This is a core requirement for authenticated Windows scanning.
A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?
Allow the scanner's public key in the authorized_keys file for the scan account
Authenticated SSH scans typically use a key pair generated by the scanner. If the scanner's public key is not present in the target account's authorized_keys file, the scanner cannot authenticate even when manual password logins succeed. Adding the scanner's public key to the authorized_keys file for the scan account directly resolves this failure.
Enable password authentication on the target hosts
Change the SSH port on the targets to 2222
Disable SELinux on the target hosts
A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)
Launch a denial-of-service test against the production application to check resilience
Use a network protocol analyzer to capture all traffic between the tester and the application
Perform manual testing of authentication and session management flows
Manual testing is essential for logic flaws, broken authentication, and session management issues that automated scanners often miss. By exercising login, logout, password reset, and session fixation scenarios by hand, the tester uncovers vulnerabilities that require contextual understanding, which complements the automated scan and increases overall assessment quality.
Run an automated web vulnerability scanner such as OWASP ZAP against the application
OWASP ZAP is an open-source web application scanner that can crawl the application and detect common issues like SQL injection, cross-site scripting, and misconfigurations. Including it provides broad, repeatable coverage and a baseline of findings that manual testing can then validate and expand upon, making it an appropriate part of a combined approach.
Run a full TCP port scan of the web server before testing the application
Want more Vulnerability Scanning and Penetration Testing practice?
Practice this domainAn enterprise network administrator needs to manage Windows 10 feature updates across a heterogeneous fleet containing both Enterprise and Professional editions. Which deployment methodology natively supports setting a target release version to freeze clients on a specific version like 21H2 while blocking automatic upgrades to later versions?
Windows Update for Business configured via Group Policy to specify a target release version
Windows Update for Business enables administrators to define a specific target version, such as Windows 10 version 21H2, directly through Group Policy or MDM solutions. This capability ensures endpoints remain pinned to that exact release until the policy is explicitly changed, preventing unexpected disruptions from subsequent annual feature upgrades.
Windows Server Update Services automatic approval rules targeting all newly released operating system updates
Consumer Windows Update settings modified through local registry edits on each individual workstation
Delivery Optimization peer-to-peer distribution bandwidth throttling applied via Local Group Policy
Microsoft releases major Windows feature updates under a predictable cadence as part of the Windows as a Service model. How often are Windows 10 and Windows 11 Enterprise feature updates officially released under the modern servicing model?
Every month alongside regular cumulative security patches
Every six months with equal priority given to spring and autumn releases
Once every year, specifically during the second half of the calendar year
Microsoft transitioned feature updates for Windows to an annual release cadence occurring in the second half of the calendar year (H2). This predictable annual schedule simplifies IT planning, allowing organizations to establish consistent validation and deployment pipelines.
Once every three years to coincide with major hardware refresh cycles
An IT security team is auditing Windows Update for Business configurations across a multi-site enterprise. Which TWO methods can be utilized by administrators to successfully deploy and enforce these cloud-linked update policies? (Choose TWO)
Group Policy Objects (GPOs) applied through Active Directory domains
Windows Update for Business policies delivered through Group Policy Objects let Active Directory domain administrators centrally enforce cloud-linked update settings across sites, leveraging existing domain infrastructure and computer-scoped policy application rather than relying solely on Intune or MDM channels.
Mobile Device Management (MDM) platforms such as Microsoft Intune
Cloud-based MDM solutions like Microsoft Intune provide native configuration profiles specifically designed to manage Windows Update for Business rings. These platforms allow seamless policy enforcement for remote and cloud-only corporate devices without requiring line-of-sight to an Active Directory domain.
Manual execution of local PowerShell scripts by end-users with standard privileges
Direct packet injection via public Wi-Fi access points during routine employee travel
Editing local security policy templates manually on every individual client workstation
A security administrator is troubleshooting an enterprise client that repeatedly fails to complete a major Windows feature upgrade, automatically triggering a rollback. Which built-in command-line utility should the administrator use to examine detailed migration logs, error codes, and rollback triggers?
SFC.exe /scannow to inspect operating system file integrity
DISM.exe /Online /Cleanup-Image /RestoreHealth to repair component stores
SetupDiag.exe to automatically parse update setup logs and identify failure reasons
SetupDiag is the designated Microsoft utility that scans setup log files, extracts error codes, and details the exact conditions that caused a Windows feature update to fail and rollback. This tool dramatically accelerates troubleshooting by pointing directly to offending drivers or software.
GPResult.exe /h report.html to generate a comprehensive group policy diagnostic report
A security analyst is reviewing the update history of a Windows 10 Enterprise device managed by Windows Update for Business (WUfB). The analyst notices that a critical security update was installed 30 days after its release, even though no deferral policies were configured. Which factor is the most likely cause for the delayed installation?
The device was configured to use a Windows Update for Business deferral for quality updates.
The update was blocked by a Windows Defender Application Control (WDAC) policy.
The device was offline or in sleep mode during the update's initial release period.
Windows Update for Business schedules updates based on device activity and connectivity. If the device is offline, in sleep mode, or not connected to the internet during the update's release, it will not download and install the update until it becomes active and connected. This can cause delays even without deferral policies. The 30-day delay suggests the device missed the initial release window due to being offline or inactive, which is a common cause in WUfB environments.
The update was not approved in Windows Server Update Services (WSUS).
A security administrator manages a fleet of Windows 10 Enterprise devices that must remain on version 1809 because a critical line-of-business application is only certified for that build. The organization uses Windows Update for Business (WUfB) and wants to prevent these devices from receiving feature updates for 18 months while still receiving quality updates. Which WUfB setting should the administrator configure?
Disable the Windows Update service and manage quality updates through a third-party patch management tool.
Set the feature update deferral period to 365 days and enable Pause feature updates for 35 days.
Assign the devices to the Semi-Annual Channel (Targeted) ring and set a 365-day feature update deferral.
Configure a Windows Update for Business target version using the TargetReleaseVersion and TargetReleaseVersionInfo policies.
TargetReleaseVersion and TargetReleaseVersionInfo are the supported WUfB policies to pin a device to a specific Windows feature update version. Setting the target version to 1809 prevents the device from moving to a later feature update while still allowing quality updates. This is the correct way to keep devices on a specific build for compatibility.
Want more Windows as a Service practice?
Practice this domainAn administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?
Immediately terminate the process using the task manager.
Perform a full system backup to an external network share.
Isolate the infected host from the network via switch port shutdown.
Network isolation successfully severs the communication channel between the malware and the attacker's command-and-control server. This containment step halts data exfiltration and remote command execution while leaving the host powered on, allowing for the secure collection of volatile memory and disk images for post-incident forensic investigation.
Run a full scan with the local antivirus engine.
Which security control is most effective at preventing the execution of unauthorized or malicious software by enforcing a 'deny-by-default' policy on a workstation?
Endpoint Detection and Response (EDR) agents.
Next-Generation Antivirus (NGAV) with behavioral analysis.
Application Whitelisting (e.g., AppLocker or WDAC).
Application whitelisting explicitly restricts execution to only approved binaries, scripts, and installers. By implementing a default-deny policy, it ensures that any unauthorized or malicious software—regardless of whether it is known to security vendors—will be blocked from executing on the host, providing a robust security posture.
Host-based Intrusion Prevention System (HIPS).
A security analyst is concerned about Fileless Malware attacks. Which technique is most effective for detecting code that resides only in memory without writing files to the disk?
Deploying a traditional antivirus signature update.
Enabling PowerShell Script Block Logging.
PowerShell Script Block Logging records the full content of code executed by the PowerShell engine. Since fileless malware frequently uses obfuscated PowerShell scripts for execution, this logging mechanism captures the de-obfuscated commands in memory, allowing for detection of malicious activity that never touches the disk.
Scanning the hard drive for unauthorized startup files.
Performing integrity checks on system binaries.
Which of the following describes the primary goal of using a 'Honeytoken' in an environment to mitigate malicious code and insider threats?
To automatically patch vulnerabilities in real-time.
To serve as a decoy for detecting unauthorized access.
The purpose of a honeytoken is to act as a detection mechanism. By creating a resource that serves no business purpose, any interaction with it serves as a clear indicator of malicious intent, allowing security teams to respond immediately to threats that have evaded other detection controls.
To encrypt sensitive data for long-term storage.
To provide a secure sandbox for testing malware.
Which THREE of the following are primary defensive strategies to mitigate the risk of 'Living off the Land' (LotL) attacks?
Restrict access to administrative tools via Constrained Language Mode.
Constrained Language Mode (CLM) in PowerShell limits the access to sensitive .NET types and commands, making it harder for attackers to use the shell for malicious purposes. This restricts the power of the tool, ensuring that attackers cannot easily perform advanced memory-based operations or API calls.
Increase the frequency of system reboots.
Enable granular command-line auditing and logging.
Detailed auditing of command-line arguments is essential to detect LotL techniques. Since the tools are legitimate, the indicator of compromise is often the specific command string used. Logging these commands allows security teams to identify deviations from normal administrative activity and respond to potential malicious usage in real-time.
Implement Principle of Least Privilege for administrative accounts.
Limiting the privilege of administrative accounts ensures that even if a tool is abused, the damage is restricted. If a standard user account is compromised, the attacker cannot use powerful administrative tools that require elevated permissions, thereby neutralizing a major portion of the attacker's toolkit and capabilities.
Disable all network logging to save disk space.
A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?
Configure AppLocker default rules to allow only administrators to run PowerShell scripts in the environment.
Disable the Windows Script Host on all workstations by setting the Enabled registry value under WSH settings to 0.
Add the finance department's subnet to the Microsoft Defender Antivirus network inspection exclusion list.
Enable PowerShell script block logging and module logging through Group Policy, then collect the events in Windows Event Forwarding for analysis.
Script block logging records the de-obfuscated script content that PowerShell actually executes, even when the command line is Base64-encoded, and module logging captures pipeline execution details. Forwarding those events to a central collector preserves the decoded payload for investigation while giving defenders visibility into the malicious behavior, directly mitigating this encoded PowerShell execution scenario.
Want more Malicious Code and Exploit Mitigation practice?
Practice this domainAn incident responder needs to determine the last time a specific user interacted with a Windows workstation. Which registry hive should be analyzed to retrieve the LastWrite time of the user's NTUSER.DAT file?
SYSTEM hive
SAM hive
SOFTWARE hive
The user's NTUSER.DAT hive
The NTUSER.DAT hive is the root of the HKEY_CURRENT_USER registry branch. Examining the file system metadata for this specific file directly reveals the LastWrite time, indicating when the hive was last flushed to disk, which corresponds to the last time the user profile was active.
Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?
Event ID 4625
Event ID 4624 with Logon Type 3
Event ID 4624 is the standard success audit for logons. Logon Type 3 is explicitly defined by Microsoft as a network logon, which occurs when a user or computer connects to a shared resource or service on the target machine from a remote source location.
Event ID 4624 with Logon Type 2
Event ID 4672
During a forensic examination, you find a Prefetch file named 'MALWARE.EXE-A1B2C3D4.pf'. What is the significance of the hexadecimal string appended to the filename?
It is a randomized identifier generated at system boot.
It represents the hash of the file's content.
It is a hash derived from the file's execution path.
The hash is calculated using the full path of the executable. This allows the system to store distinct prefetch information for applications sharing the same name but residing in different directories, providing forensic investigators with the exact location where the binary was executed from.
It is the timestamp of the last execution.
Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?
It defines the system's default language settings.
It maps Security Identifiers (SIDs) to user profile directories.
ProfileList is the authoritative source for locating where a user's profile resides on the disk. For an investigator, this is essential to verify account existence and identify the correct directory path for further analysis of user-specific artifacts that might contain evidence of attacker activity.
It logs every application the user has executed.
It lists all installed software on the system.
When investigating a Windows system, which file system feature is responsible for recording the file metadata including timestamps for created, modified, and accessed (MACE) times?
Registry hives
Master File Table (MFT)
The MFT is a relational database that acts as the backbone of NTFS. It stores the metadata for every file and folder on the partition, including the primary timestamps (Standard Information and File Name attributes) used for forensic timeline analysis and detecting file modification or deletion events.
Event Logs
Prefetch files
An incident responder is analyzing a Windows 10 workstation that is suspected of being used to exfiltrate data. The responder runs 'wevtutil qe Security /q:"*[System[(EventID=5156)]]" /f:text' but finds no events. Which action will most reliably produce the network connection telemetry the responder needs for this investigation?
Set the Security log retention method to 'Overwrite events as needed' and increase the maximum log size to 1 GB.
Run 'netsh trace start capture=yes' and review the resulting ETL file in Event Viewer under the Microsoft-Windows-TCPIP operational log.
Enable the 'Audit Process Creation' policy and configure the 'Include command line in process creation events' setting to capture outbound connections.
Enable the 'Audit Filtering Platform Connection' policy under Advanced Audit Policy Configuration and ensure the Security log is large enough to retain events.
Event ID 5156 is logged only when the Filtering Platform Connection subcategory is audited. By default it is not enabled, so the query returns nothing. Enabling this subcategory via Advanced Audit Policy Configuration and provisioning sufficient Security log capacity allows the responder to capture allowed and blocked connection events with process, user, and port details needed to trace exfiltration.
Want more Windows Forensics practice?
Practice this domainAn administrator observes that internal users are receiving certificate warnings when accessing a new internal web application. The organization uses an internal Certificate Authority (CA). What is the primary cause of this behavior?
The server certificate has expired, triggering a validity date error in the browser.
The web server failed to send the intermediate certificate in the handshake process.
The internal Root CA certificate is not installed in the client's local trust store.
Web browsers rely on the local certificate store to validate the identity of web servers. If the issuing CA's root certificate is not present in the user's trusted root certification authorities store, the browser will signal that the site's identity cannot be verified, resulting in a security warning.
The web application is utilizing an outdated TLS version that browsers no longer support.
A developer wants to prevent sensitive cookies from being transmitted over unencrypted HTTP connections. Which cookie attribute is specifically designed to enforce this requirement?
HttpOnly
SameSite=Strict
Secure
The Secure flag instructs the browser to restrict the cookie transmission to encrypted (HTTPS) connections only. This is the primary mechanism for ensuring that sensitive session identifiers are not exposed in plaintext during network transit, providing a necessary layer of protection against sniffing and interception of data.
Path=/secure
Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?
Cross-Site Request Forgery (CSRF)
Cross-Site Scripting (XSS) session theft
HttpOnly prevents JavaScript from reading the cookie content. In an XSS scenario, an attacker typically tries to exfiltrate the session cookie to an external server. With the HttpOnly attribute, the browser rejects requests from scripts to read the cookie, effectively neutralizing this specific theft vector during an injection.
Man-in-the-Middle (MitM) interception
SQL Injection (SQLi)
During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?
Complete server crash due to memory corruption
Database downtime caused by excessive query volume
Exhaustion of available connection slots
Slowloris works by opening many connections and sending headers very slowly, never finishing the request. Since the server keeps these connections open while waiting for the full request, it eventually reaches its maximum connection limit, preventing any new legitimate users from connecting to the application.
Unauthorized access to the application root directory
A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA during the handshake. Which security weakness does this cipher suite selection introduce?
It lacks forward secrecy because the RSA key exchange does not generate ephemeral session keys.
TLS_RSA_WITH_AES_128_CBC_SHA uses static RSA key exchange, meaning the premaster secret is encrypted with the server's long-term RSA key. If an attacker records the encrypted session and later obtains the server's private key, they can decrypt all past sessions. This violates forward secrecy, a critical property for protecting historical traffic. Modern best practice mandates ECDHE or DHE cipher suites to ensure each session has unique ephemeral keys.
It uses AES in CBC mode, which is vulnerable to padding oracle attacks such as POODLE.
It uses SHA-1 for integrity, which is considered cryptographically broken for MACs.
It allows downgrade to export-grade cryptography because of the RSA key exchange.
A security analyst is examining a web application that uses HTTP Strict Transport Security (HSTS). The analyst notices that the HSTS header is only sent on HTTPS responses and includes the 'preload' directive. Which additional measure must be taken to ensure the domain is included in browser preload lists?
Submit the domain to the HSTS preload list maintained by Google, and ensure the header includes 'includeSubDomains' and a max-age of at least one year.
To be included in browser HSTS preload lists, the domain must be submitted to the preload list service (e.g., hstspreload.org) and meet specific requirements: the HSTS header must include 'includeSubDomains', 'preload', and a max-age of at least 31536000 seconds (one year). The preload directive signals intent, but submission is a separate manual step. This ensures the domain is hardcoded into browsers, providing protection even on the first visit.
Ensure the HSTS header is sent with a max-age of at least six months and includes the 'preload' directive, then submit the domain to the preload list.
Configure the server to redirect all HTTP requests to HTTPS with a 301 status code and include the HSTS header in the redirect response.
Add the 'preload' directive to the HSTS header and wait for browsers to automatically discover and add the domain to their preload lists.
Want more Web Communication Security practice?
Practice this domainAn administrator observes unauthorized devices connecting to an enterprise wireless network using WPA2-Personal. Which mitigation strategy best prevents credential sharing and ensures unique authentication for every employee?
Implement MAC address filtering on all wireless access points.
Transition to WPA2-Enterprise utilizing 802.1X authentication with EAP-TLS.
WPA2-Enterprise leverages 802.1X, which requires unique authentication per user, typically via certificates or domain credentials. This approach prevents credential sharing because each session is cryptographically bound to an individual identity, allowing administrators to revoke specific access without impacting the entire wireless network architecture or changing shared passwords.
Increase the PSK complexity to a 64-character alphanumeric string.
Enable hidden SSIDs to prevent unauthorized discovery.
Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?
Channel 1 selection is a performance concern.
WPS enabled allows for PIN-based brute-force attacks.
WPS (Wi-Fi Protected Setup) is highly insecure because the PIN validation process is flawed. Attackers can brute-force the PIN in small segments, eventually retrieving the network PSK. This vulnerability exists regardless of how strong the actual WPA2 password is, making it a critical security risk for any network.
WPA2-PSK is insufficient for modern enterprise needs.
Management Frame Protection is disabled.
Which THREE of the following actions are considered best practices when hardening an enterprise wireless infrastructure?
Disable WPS on all wireless access points.
WPS is inherently insecure due to design flaws in the PIN exchange process. Disabling it completely eliminates this attack vector, which is a mandatory step for any secure deployment. Failure to disable WPS leaves the network vulnerable to rapid credential recovery through automated brute-force tools.
Implement WPA3 or WPA2-Enterprise with 802.1X.
WPA3 provides superior encryption and forward secrecy, while WPA2-Enterprise with 802.1X mandates individual user authentication. Both methods are superior to PSK-based systems, as they eliminate shared credentials and significantly raise the bar for attackers attempting to compromise individual wireless sessions or the network as a whole.
Enable SSID hiding to conceal the network.
Deploy a WIPS for continuous monitoring and rogue detection.
A WIPS is essential for detecting unauthorized access points, man-in-the-middle attempts, and denial-of-service attacks. By providing real-time visibility into the radio spectrum, it allows security teams to respond to threats that standard firewalls or endpoint security solutions cannot see, making it vital for wireless network integrity.
Use WEP for legacy hardware compatibility.
A security auditor notices that wireless clients are frequently disconnected by de-authentication frames that contain a spoofed MAC address of the access point. What is the auditor witnessing?
A standard re-keying process defined by WPA2 standards.
A de-authentication Denial of Service (DoS) attack.
De-authentication attacks exploit the lack of management frame integrity in older 802.11 standards. By spoofing the AP's address, the attacker forces clients to drop their connection. This is a common method for disrupting service or preparing a target for an Evil Twin or packet interception attack.
An automated load balancing mechanism on the AP.
A probe response flood from an adjacent network.
Which TWO of the following statements are true regarding the use of WPA3 compared to WPA2?
WPA3 uses SAE to replace the vulnerable WPA2 PSK exchange.
SAE (Simultaneous Authentication of Equals) provides stronger protection than the PSK mechanism used in WPA2. It defends against offline dictionary attacks because the key exchange does not rely on a simple hash of the password, preventing attackers from capturing the handshake to crack it later.
WPA3 is fully backward compatible with all WEP-based devices.
WPA3 mandates the use of Protected Management Frames (PMF).
PMF is mandatory in WPA3, ensuring that management frames are cryptographically signed. This prevents attackers from spoofing de-authentication frames to disconnect clients, which is a significant improvement over WPA2, where PMF was optional and rarely implemented in standard client-side deployments.
WPA3 removes the requirement for 802.1X authentication entirely.
WPA3 encryption is strictly limited to 64-bit keys.
A security analyst at a financial firm is reviewing wireless traffic captured near the executive conference room. The capture shows a flood of 802.11 management frames with source addresses set to the company's legitimate AP MAC address, but the frames are not encrypted and are arriving at a high rate. Which type of attack is most likely occurring?
A deauthentication flood using spoofed management frames.
The flood of unencrypted 802.11 management frames with a spoofed AP MAC address is characteristic of a deauthentication attack. These frames are sent to disconnect clients from the legitimate AP, often as a precursor to an evil twin or capture of the WPA handshake. The high rate and spoofed source confirm this is not normal traffic.
A rogue access point broadcasting a duplicate SSID to lure clients.
A KRACK key reinstallation attack against the WPA2 four-way handshake.
A WPA3 Dragonblood downgrade attack forcing the use of WPA2.
Want more Wireless Network Security practice?
Practice this domainYou are auditing a Windows Server environment and identify that a service is configured to log on as a 'Group Managed Service Account' (gMSA). What is the primary security advantage of using this account type over a standard domain user account?
They enable Kerberos constrained delegation by default.
They automatically rotate passwords without service restarts.
gMSAs manage complex, long, and randomly generated passwords that are automatically rotated by the Active Directory Key Distribution Service. This eliminates the risk associated with human-managed static passwords and prevents service interruptions during rotation, ensuring that credentials are never stale or vulnerable to offline cracking attempts.
They bypass the need for an SPN registration.
They allow for local interactive logons on all domain controllers.
An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?
Task Scheduler
Services.msc
Group Policy Management Console (GPMC)
GPMC provides the interface to define and deploy Group Policy Objects. These objects allow administrators to centrally configure service security, startup behaviors, and account permissions across the entire Active Directory domain, ensuring a uniform and auditable security baseline for all managed Windows services and host systems.
Local Security Policy (secpol.msc)
When auditing an Azure environment, you notice that a Virtual Machine is utilizing a User-Assigned Managed Identity. How does this differ from a System-Assigned Managed Identity?
User-assigned identities do not require Entra ID authentication.
System-assigned identities can be shared across multiple resources.
User-assigned identities exist as separate, independent Azure resources.
A user-assigned identity is a standalone Azure resource. This allows it to be assigned to multiple Azure resources (like VMs or App Services) and managed independently of the lifecycle of those resources, providing better scalability and centralized control over permissions in complex, multi-service cloud deployments.
System-assigned identities provide more granular permission scopes.
You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?
The service account lacks the 'Log on as a service' right.
The service account credentials are invalid or locked.
Error 0x8007052e is the Windows system code for 'Logon failure: unknown user name or bad password'. This confirms that the service manager attempted to authenticate the service account with Active Directory, but the credentials were rejected, likely due to a password mismatch, expired password, or account lockout.
The network path to the domain controller is unreachable.
The service binary is corrupted or missing.
A security engineer is hardening a Windows Server 2022 that hosts a Microsoft SQL Server instance. The server is domain-joined, and the SQL Server service currently runs under a domain user account. The engineer wants to implement a solution that provides automatic password management, supports Kerberos authentication, and allows the service to access network resources. The solution must also minimize the risk of password reuse across multiple servers. Which of the following should the engineer implement?
Group Managed Service Account (gMSA)
A gMSA is a domain account whose password is managed by Active Directory and automatically rotated. It supports Kerberos authentication, allows the service to access network resources, and can be shared across multiple servers without password reuse. This directly meets all requirements and is the recommended solution for services like SQL Server.
Standalone Managed Service Account (sMSA)
Virtual Service Account
Local Service account
A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?
Use virtual accounts for each service.
Create standard domain user accounts and configure them with a long, complex password that never expires.
Configure each service to use a standalone Managed Service Account (sMSA).
Implement Group Managed Service Accounts (gMSAs) for the services.
Group Managed Service Accounts (gMSAs) are domain accounts whose passwords are managed by Active Directory and rotated automatically every 30 days. They can be used across multiple servers, and the password is not stored locally; instead, the Key Distribution Service (KDS) root key is used to derive the password. This meets all the stated requirements.
Want more Windows Services and MS Cloud practice?
Practice this domainThe GSEC exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 26 domains: Network Security Devices, Windows Security Infrastructure, macOS Security, Cryptography Application, Defense in Depth, Defensible Network Architecture, Access Control and Password Management, Cryptography, Endpoint Security, Windows Automation and Auditing, Networking and Protocols, Linux Fundamentals, Log Management and SIEM, Security Frameworks and CIS Controls, Container Security, Incident Handling and Response, Linux Security and Hardening, Windows Access Controls, Virtualization, Cloud, and AI Essentials, Vulnerability Scanning and Penetration Testing, Windows as a Service, Malicious Code and Exploit Mitigation, Windows Forensics, Web Communication Security, Wireless Network Security, Windows Services and MS Cloud. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official GIAC GSEC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.