Sample questions
GIAC Security Essentials practice questions
When designing a secure container orchestration strategy, which approach best minimizes the impact of a compromised container on the host kernel?
Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?
A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to e…
A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisio…
A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query paramet…
A security engineer is configuring a new AWS S3 bucket to store sensitive PII. Which combination of settings best adheres to the principle of least privilege for the bucket policy?
Virtualization, Cloud, and AI EssentialsmediumSee the answer and why each option is right or wrong →A financial services firm has deployed a next-generation firewall at its internet perimeter, host-based firewalls on every workstation, and VLAN segmentation between departments. D…
Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretati…
An organization is implementing TLS 1.3 for a new customer portal. During the cipher suite negotiation phase, the security engineer needs to ensure that perfect forward secrecy is…
Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?
During a forensic examination, you find a Prefetch file named 'MALWARE.EXE-A1B2C3D4.pf'. What is the significance of the hexadecimal string appended to the filename?
An organization is migrating to a hybrid cloud environment. Which security control is most effective for preventing unauthorized lateral movement between virtual machines residing…
Virtualization, Cloud, and AI EssentialsmediumSee the answer and why each option is right or wrong →After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were no…
A penetration tester is reviewing the TLS configuration of an e-commerce web server. The tester observes that the server prefers the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA durin…
A security analyst is reviewing logs from a Linux web server that has been compromised. The analyst notices a large number of requests to a specific URL that include encoded charac…
A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-i…
A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint de…
An administrator observes unauthorized devices connecting to an enterprise wireless network using WPA2-Personal. Which mitigation strategy best prevents credential sharing and ensu…
A retail company is adopting the CIS Critical Security Controls and wants to prioritize its efforts. According to the CIS Controls, which of the following is the first basic contro…
A retail company runs a stateful firewall at its internet edge. Users complain that long-lived SSH sessions to a partner are being dropped roughly every hour even though no idle ti…
A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to deter…
A responder is preparing to image a compromised Windows server's memory before shutting it down. The server hosts a critical database and management insists on minimal downtime. Wh…
A retail company is deploying a large language model (LLM) based customer support assistant that has access to internal order databases through a tool-calling interface. The securi…
Virtualization, Cloud, and AI EssentialsmediumSee the answer and why each option is right or wrong →A security engineer is deploying a network-based intrusion detection system (NIDS) to monitor traffic entering and leaving a data center. The engineer needs to ensure the sensor ca…