Courseiva
Defense in Depth →hardMultiple Select

GSEC Defense in Depth Practice Question

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

⚠ Common exam trap

The trap here is treating convenience measures such as disabling SELinux or granting broad sudo as acceptable hardening, when they actually remove layers of defense.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require all build servers to authenticate users with individual SSH keys and disable password authentication.

Reducing the impact of a compromised build server requires layered constraints: container isolation with dropped capabilities and read-only filesystems limits what code can do, HSM-backed signing keys with dual authorization protect the supply chain, and per-user SSH keys harden initial access. Disabling SELinux and granting unrestricted sudo both expand attacker privileges, so they weaken rather than strengthen the layered defense.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the build service account passwordless sudo access to all commands to simplify automation.

    Why it's wrong here

    Passwordless sudo to all commands means a compromise of the build service account yields full root control immediately. This removes privilege boundaries and maximizes the impact of an intrusion instead of containing it. It is the opposite of least privilege and undermines the defense in depth strategy the team is pursuing.

  • ✓

    Require all build servers to authenticate users with individual SSH keys and disable password authentication.

    Why this is correct

    Per-user SSH keys with password authentication disabled prevent credential reuse and brute-force attacks against the build host. Individual keys create accountability and allow revocation without disrupting other engineers. This strengthens identity controls at the host layer, making initial compromise harder and limiting attacker movement.

  • ✗

    Disable SELinux on the build server to avoid build failures caused by mandatory access control denials.

    Why it's wrong here

    Disabling SELinux removes a mandatory access control layer that confines processes to defined domains. Doing so makes a compromised build process more powerful, not less, because it can access files and sockets outside its intended role. This directly weakens defense in depth and contradicts the goal of reducing the impact of compromise.

  • ✓

    Store build signing keys on a hardware security module (HSM) that requires dual authorization to use.

    Why this is correct

    An HSM isolates private signing keys so they never exist in plaintext on the build server. Dual authorization adds a second human control, so a single compromised account cannot sign malicious artifacts. This protects the integrity of the software supply chain even if the build host is fully compromised.

  • ✓

    Run build jobs inside containers that drop all Linux capabilities and use a read-only root filesystem.

    Why this is correct

    Dropping all capabilities and mounting the root filesystem read-only constrains what a compromised build process can do. An attacker cannot load kernel modules, change file ownership, or persist on disk through the container image. This limits blast radius, which is a core defense in depth objective at the host and application layers.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.