Courseiva

GIAC Security Essentials (GSEC) — Questions 151–225

351 questions total · 5pages · All types, answers revealed

Page 2

Page 3 of 5

Page 4
151
MCQhard

A healthcare provider is implementing CIS Control 3: Data Protection. They must ensure that data at rest is encrypted according to the safeguards. Which of the following activities directly satisfies the requirements of CIS Control 3 for data at rest?

A.Enabling full-disk encryption on all endpoints and servers that store protected health information.
B.Deploying a data loss prevention (DLP) solution to monitor outbound email containing patient data.
C.Configuring database backup files to be stored in a separate physical location with access controls.
D.Implementing TLS 1.2 for all web traffic to and from the electronic health record system.
AnswerA

CIS Control 3 explicitly requires encryption of data at rest on end-user devices and servers. Full-disk encryption protects data if a device is lost or stolen. This directly addresses the safeguard for data at rest, making it the correct action.

Why this answer

Full-disk encryption directly satisfies the CIS Control 3 requirement to encrypt data at rest on endpoints and servers. It ensures that if a device is lost or stolen, the stored data remains unreadable. Other options address data in transit, monitoring, or physical security, which are important but do not meet the specific encryption-at-rest mandate.

Exam trap

The trap here is confusing data-in-transit encryption with data-at-rest encryption, and assuming that any security measure involving data satisfies the control.

152
MCQmedium

What is the primary purpose of the 'Notarization' process for macOS applications?

A.To provide full-disk encryption for the application data.
B.To scan for malicious code and verify developer identity.
C.To restrict application access to user contact data.
D.To enforce system-level integrity of the kernel.
AnswerB

Notarization uses automated tools to scan applications for known malware and verify that they are properly signed by a verified Apple Developer account. This ensures that users are protected from installing malicious software, acting as a crucial pre-execution security check for all macOS applications.

Why this answer

Notarization is an automated system that scans software for malicious content and verifies that it is signed by a registered developer. It provides a level of assurance to users that the software has been reviewed by Apple. For GSEC, understanding notarization is crucial because it bridges the gap between basic code signing and runtime execution, ensuring that even signed software meets baseline security standards before deployment.

Exam trap

Candidates often assume notarization is purely for software distribution or licensing, missing the critical security component where Apple scans for malicious code before execution.

153
MCQhard

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

A.The traffic is permitted because the second rule matches the source subnet.
B.The traffic is denied because the first rule matches and terminates evaluation.
C.The traffic is permitted because permit rules take precedence over deny rules.
D.The router generates an error because the ACL rules are contradictory.
AnswerB

The router processes the ACL in a top-down fashion. The first rule denies all traffic to 10.0.5.5 on port 80. Since the packet matches this criteria, the evaluation stops, and the router silently discards the packet. The permit rule located on the second line is never reached.

Why this answer

Cisco standard and extended ACLs process rules sequentially from top to bottom. The first rule explicitly denies any IP traffic to the host 10.0.5.5 on port 80. Because this deny rule is matched first, the router immediately drops the packet before evaluating subsequent lines.

Even though the second rule would have permitted the traffic, it is unreachable due to the specificity and position of the initial deny statement.

Exam trap

Candidates often assume that because a permit rule exists for the subnet, the traffic will be allowed, forgetting that ACLs are processed top-down and the first match wins.

154
MCQmedium

Which of the following represents an example of applying defense in depth at the host level?

A.Installing a web application firewall at the network edge.
B.Configuring local host firewalls and endpoint detection and response (EDR) software.
C.Implementing multi-factor authentication for corporate VPN access.
D.Deploying a network intrusion detection system (NIDS) in promiscuous mode.
AnswerB

These two tools together at the host level create a layer of defense that operates independently of network-wide controls. The host firewall limits incoming and outgoing traffic, while EDR provides continuous monitoring and threat prevention for local processes, effectively creating a defense in depth posture on the machine.

Why this answer

Host-level defense in depth involves implementing multiple security controls directly on individual servers or workstations to create a resilient environment. If an attacker bypasses the network perimeter, host-based controls like EDR and local firewalls provide the final barrier. This multi-faceted approach ensures that even if a network segment is compromised, the specific endpoint remains protected and monitored, preventing widespread damage and aiding in rapid incident response and threat isolation.

Exam trap

Candidates often pick network-based controls like firewalls or IDS. The question specifically asks for 'host-level' defense, requiring controls that exist directly on the endpoint itself.

155
MCQhard

A security operations center (SOC) ingests NetFlow records into its SIEM. An analyst wants to detect potential data exfiltration over the network. Which SIEM correlation strategy is most effective for this purpose?

A.Alert when any host initiates a connection to a country that is not on an approved list.
B.Correlate outbound traffic volume with destination IP reputation and unusual port usage, and alert on deviations from the host's historical baseline.
C.Alert when any internal host sends more than 1 GB of data to an external IP address within an hour.
D.Monitor for DNS queries to known command-and-control domains and alert on any match.
AnswerB

This strategy combines multiple weak indicators (volume, destination reputation, port) and behavioral baselining to increase confidence. Exfiltration often involves transfers to unknown or low-reputation IPs on non-standard ports, and volume that is anomalous for that specific host. Correlating these factors reduces false positives and catches stealthy exfiltration that avoids simple thresholds.

Why this answer

Data exfiltration detection benefits from behavioral baselining and multi-factor correlation. By learning each host's normal outbound traffic patterns and combining volume anomalies with destination reputation and port usage, the SIEM can flag suspicious transfers that would be missed by static thresholds or country blocks alone.

Exam trap

The trap here is focusing on a single indicator such as volume or geography, when effective exfiltration detection requires correlating multiple contextual factors and baselining normal behavior.

156
MCQhard

A healthcare provider is aligning its security program with the CIS Critical Security Controls. The security team is tasked with implementing CIS Control 1: Inventory and Control of Enterprise Assets. Which of the following activities is the most critical first step to ensure the control is effectively implemented?

A.Creating a formal policy that defines what constitutes an enterprise asset and assigns ownership for maintaining the inventory.
B.Deploying an automated asset discovery tool to scan the network for all connected devices.
C.Implementing a configuration management database (CMDB) to store asset information.
D.Conducting a manual inventory of all assets in the data center.
AnswerA

CIS Control 1 begins with establishing and maintaining an inventory of enterprise assets. The foundational step is to define the scope and create a policy that specifies what assets are in scope, who owns them, and how the inventory will be maintained. This ensures that subsequent technical steps, like discovery and tracking, are aligned with business requirements and have clear accountability.

Why this answer

CIS Control 1 emphasizes the importance of a formalized process for inventory and control of enterprise assets. The initial step is to create a policy that defines the scope and assigns ownership. This ensures that the inventory is accurate, maintained, and aligned with organizational needs.

Without this governance, technical implementations may lack direction and accountability, leading to an ineffective control.

Exam trap

The trap here is focusing on the technical tool (such as an automated discovery tool or CMDB) as the first step, while overlooking the need for policy and ownership definition.

157
Multi-Selecthard

An organization is hardening its internal corporate network architecture to prevent unauthorized hosts from connecting to switch ports in common areas and conference rooms. Which TWO configurations should the network engineering team implement to achieve this security objective? (Choose TWO)

Select 2 answers
A.Enabling 802.1X port-based authentication integrated with a RADIUS server and extensible authentication protocol.
B.Configuring static routing protocols on all access layer switches to bypass dynamic route poisoning attacks.
C.Configuring switch port security to restrict the maximum number of dynamically learned MAC addresses per interface.
D.Deploying unmanaged network hubs in conference rooms to simplify physical cable management and port density.
E.Disabling spanning tree protocol root guard on all core enterprise switches to accelerate topology convergence times.
AnswersA, C

802.1X port-based authentication requires every connecting client to provide valid credentials to an authentication server before the switch port transitions to an active state. This robust mechanism prevents unauthorized physical devices from accessing the internal network environment.

Why this answer

Implementing 802.1X port-based authentication forces every connecting device to authenticate against a central directory service before gaining network access. Combined with port security limits that restrict the maximum number of registered MAC addresses per switch port, organizations effectively block rogue devices and unauthorized hardware from establishing unauthorized network connections in public areas.

Exam trap

Candidates often choose physical locks or basic password policies. These do not address the network-level requirement of controlling access to specific switch ports for unknown devices in public areas.

158
MCQhard

A security architect is designing a system that requires cryptographic keys to be generated, stored, and used without ever exposing the private key material to the operating system. The keys must be usable for TLS server authentication and must support high transaction volumes. Which of the following solutions BEST meets these requirements?

A.A cloud key management service (KMS) that stores keys in a multi-tenant environment.
B.A Hardware Security Module (HSM) with TLS offloading capabilities.
C.A software-based key store protected by a strong passphrase and file system permissions.
D.A Trusted Platform Module (TPM) 2.0 chip on each server.
AnswerB

An HSM is a dedicated hardware device that generates, stores, and uses cryptographic keys within a tamper-resistant boundary. Private keys never leave the HSM in plaintext, so the operating system cannot access them. HSMs support high-performance TLS acceleration, making them suitable for high transaction volumes. This meets all requirements: key isolation and performance.

Why this answer

An HSM provides a dedicated, tamper-resistant environment where private keys are generated and used without ever leaving the device. This ensures the operating system never sees the key material. HSMs are also designed for high-performance cryptographic operations, including TLS acceleration, making them ideal for high-volume server authentication.

Exam trap

The trap here is confusing a TPM with an HSM; TPMs are for platform integrity and low-volume crypto, not high-performance TLS key protection.

159
MCQmedium

A security administrator is troubleshooting a Windows 10 Enterprise device that is not receiving feature updates from Windows Update for Business. The administrator confirms that the device is connected to the network and has the correct Windows Update for Business policies applied. The administrator suspects that a Group Policy setting is overriding the Windows Update for Business configuration. Which Group Policy setting should the administrator check first?

A.Turn off Automatic Updates.
B.Configure Automatic Updates.
C.Select when Feature Updates are received.
D.Do not connect to any Windows Update Internet locations.
AnswerD

This policy, when enabled, prevents the device from connecting to Windows Update or Windows Update for Business servers, effectively blocking updates. It can override Windows Update for Business settings by preventing the device from reaching the update service. If this policy is set, the device will not receive feature updates even if Windows Update for Business policies are correctly applied. This is a common cause of update failure in managed environments.

Why this answer

The correct answer is 'Do not connect to any Windows Update Internet locations.' This Group Policy setting prevents the device from connecting to Windows Update or Windows Update for Business, blocking feature updates. It can override Windows Update for Business configurations by cutting off access to the update service. Other policies either do not directly block updates or are part of Windows Update for Business itself.

Exam trap

The trap here is assuming that any update-related Group Policy will override Windows Update for Business, when in fact only specific policies that block connectivity or disable the service will prevent updates.

160
MCQhard

An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?

A.Enabling private VLAN edge isolation between access ports
B.Deploying 802.1X port-based network access control on access ports
C.Configuring Dynamic ARP Inspection with a DHCP snooping binding table
D.Enabling Spanning Tree Protocol on all access switches
AnswerC

Dynamic ARP Inspection intercepts ARP packets on untrusted ports and compares the sender IP and MAC against the DHCP snooping binding database. A forged reply from a MAC that does not own the gateway address is dropped before it reaches the workstation, so the victim never updates its ARP cache with the attacker's address. This directly targets the gratuitous or unsolicited ARP reply used in the on-path attack.

Why this answer

Dynamic ARP Inspection is the control specifically designed to stop forged ARP replies. By relying on the DHCP snooping binding table as its source of truth for which MAC legitimately owns which IP, the switch can drop any ARP packet whose sender information does not match an authorized binding. This blocks the attacker's spoofed reply before the workstation can poison its cache and redirect off-subnet traffic.

Exam trap

The trap here is assuming that any Layer 2 hardening feature, such as 802.1X or private VLANs, will stop ARP spoofing, when only Dynamic ARP Inspection validates ARP payloads against a trusted binding table.

161
MCQhard

A security administrator is reviewing authentication logs and notices that an attacker successfully authenticated to a VPN using a valid username and password, but the attacker did not possess the user's hardware token. The VPN is configured to require both a password and a one-time code from a hardware token. Which attack technique most likely allowed the attacker to bypass the hardware token requirement?

A.Credential stuffing
B.Pass-the-hash
C.Man-in-the-middle attack
D.Brute-force attack
AnswerC

A man-in-the-middle attack can intercept the authentication session and relay the one-time code in real time. If the attacker positions themselves between the user and the VPN, they can capture the password and the token code as the user submits them, then use them to authenticate before the code expires. This allows bypassing the hardware token requirement without possessing the physical token.

Why this answer

A man-in-the-middle attack allows an attacker to intercept and relay authentication credentials, including one-time codes, in real time. If the attacker can position themselves between the user and the VPN, they can capture both the password and the token code as they are transmitted. The attacker then uses these to authenticate before the code expires, effectively bypassing the need to physically possess the hardware token.

Other attacks like pass-the-hash, credential stuffing, or brute-force do not provide the one-time code.

Exam trap

The trap here is assuming that a hardware token makes authentication immune to interception, forgetting that real-time relay attacks can capture and reuse one-time codes.

162
MCQmedium

Which PowerShell command is used to display the current status of advanced auditing policies on a Windows system?

A.Get-AuditPolicy
B.auditpol /get /category:*
C.Get-SecurityPolicy -Advanced
D.Get-EventLog -List
AnswerB

This is the correct command-line utility used to query the system's current advanced audit policy. It outputs the status of all audited categories, allowing administrators to confirm that required auditing features are active across the entire system for comprehensive security coverage.

Why this answer

The 'auditpol /get /category:*' command is the standard CLI method to verify the current configuration of the Advanced Audit Policy. Unlike legacy policies, advanced policies allow for granular control over what events are logged, providing better precision for security analysis. Verifying these settings is a standard step in ensuring that the security telemetry collected aligns with the organizational compliance requirements.

Exam trap

Candidates often guess 'auditpol /list' or 'auditpol /query' instead of the correct '/get' switch, as these common CLI verbs feel more intuitive for retrieving configuration status.

163
MCQmedium

An organization is deploying a new VPN solution and wants to ensure that authentication credentials are not transmitted in cleartext over the internet. The security team decides to use a protocol that encapsulates authentication within a TLS tunnel. Which protocol should they implement?

A.EAP-TTLS
B.CHAP
C.PAP
D.MS-CHAPv2
AnswerA

EAP-TTLS (Extensible Authentication Protocol - Tunneled Transport Layer Security) establishes a TLS tunnel and then authenticates the client using various methods inside that tunnel. This ensures credentials are never sent in cleartext. It is commonly used in VPN and Wi-Fi authentication. The scenario requires encapsulating authentication within a TLS tunnel, which EAP-TTLS does by design, making it the correct choice.

Why this answer

EAP-TTLS encapsulates authentication within a TLS tunnel, protecting credentials from eavesdropping. PAP sends cleartext, CHAP uses a non-TLS challenge-response, and MS-CHAPv2 lacks TLS encapsulation. Only EAP-TTLS meets the requirement of transmitting authentication securely within a TLS tunnel, making it the correct protocol for the VPN deployment.

Exam trap

The trap here is assuming that any challenge-response protocol like CHAP or MS-CHAPv2 provides sufficient security, when they do not encapsulate authentication within TLS and remain vulnerable to offline attacks.

164
Multi-Selectmedium

A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)

Select 2 answers
A.Disable User Account Control (UAC) to improve user productivity
B.Install a second third-party antivirus alongside Microsoft Defender Antivirus
C.Enable the Guest account and assign it a blank password for temporary access
D.Enable PowerShell Constrained Language Mode for all users
E.Disable the Windows Script Host (WSH) to prevent execution of .vbs and .js scripts
AnswersD, E

Constrained Language Mode restricts PowerShell to a limited set of language features and blocks access to arbitrary .NET types and COM objects. This significantly hinders attackers who rely on PowerShell for fileless malware and post-exploitation. Enforcing it for all users is a valid hardening step that reduces the attack surface while still allowing many administrative scripts to run, so it is an appropriate measure.

Why this answer

Disabling Windows Script Host and enforcing PowerShell Constrained Language Mode both reduce the attack surface by limiting common attacker execution techniques. WSH is often abused for script-based malware, and Constrained Language Mode restricts PowerShell's ability to load arbitrary code. Together they harden endpoints without requiring third-party tools, while the other options either weaken security or introduce conflicts.

Exam trap

The trap here is assuming that more security products or user convenience always improve security, when disabling UAC or adding a second antivirus actually increases risk.

165
MCQeasy

During a web application audit, you determine that the server is vulnerable to a 'Slowloris' attack. What is the most likely symptom of this attack on the web server?

A.Complete server crash due to memory corruption
B.Database downtime caused by excessive query volume
C.Exhaustion of available connection slots
D.Unauthorized access to the application root directory
AnswerC

Slowloris works by opening many connections and sending headers very slowly, never finishing the request. Since the server keeps these connections open while waiting for the full request, it eventually reaches its maximum connection limit, preventing any new legitimate users from connecting to the application.

Why this answer

Slowloris is a low-bandwidth Denial-of-Service (DoS) attack that keeps connections open by sending partial HTTP requests. By never completing the request headers, the server's connection pool becomes exhausted, leaving no threads available to handle legitimate users. This is a classic example of an application-layer DoS attack, which highlights the importance of configuring proper timeout settings and resource limits on web servers like Apache or Nginx.

Exam trap

Candidates often confuse Slowloris with volumetric DDoS attacks like SYN floods. They wrongly assume the symptom is bandwidth saturation, failing to realize the server remains responsive but lacks available threads for new connections.

166
MCQmedium

An organization deploys a network-based Intrusion Detection System (IDS) in passive monitoring mode on a core switch trunk link. If the IDS detects an active external command-and-control connection to an infected internal workstation, what action does the IDS take?

A.It automatically injects TCP reset (RST) packets into the stream to terminate the active session.
B.It drops the malicious packets at the interface level to protect the internal workstation from further compromise.
C.It generates an alert log entry and notifies security analysts via SIEM integration or SNMP traps.
D.It dynamically updates the core switch routing table to quarantine the infected workstation into an isolated VLAN.
AnswerC

Passive IDS sensors monitor mirrored traffic without interfering with packet delivery. Upon detecting malicious indicators, they record the event to local logs and transmit alerts to centralized management systems and SIEM platforms for analyst review.

Why this answer

A network-based IDS operates in passive monitoring mode, receiving mirrored traffic copies via a SPAN port or network tap. Because it is deployed out-of-band, it cannot inline drop packets; instead, it generates security alerts, logs events, and can trigger external response mechanisms like SNMP traps or API calls.

Exam trap

Candidates often assume an IDS can automatically block traffic, confusing it with an IPS (Intrusion Prevention System), which sits inline and has the capability to drop malicious packets.

167
MCQhard

An enterprise network design utilizes an out-of-band management network for all core routers, firewalls, and switches. The management network is physically separated from the production data plane and uses dedicated management switches. What is the primary security advantage of this defensible architecture?

A.It completely eliminates the requirement to encrypt administrative SSH and HTTPS sessions across the network core.
B.It prevents compromised production workloads from launching lateral attacks against device management planes.
C.It automatically accelerates routing convergence times across all enterprise boundary routers by removing administrative overhead.
D.It allows network operators to utilize unauthenticated cleartext telnet connections without risking confidentiality breaches.
AnswerB

Physical separation ensures that even if an attacker completely compromises the production data plane, they cannot reach the management plane interfaces because there is no direct network path between the two distinct environments, protecting critical device controls.

Why this answer

An out-of-band management network isolates administrative traffic from production data flows, ensuring that an operational disruption or compromise of the data plane does not lock administrators out of their infrastructure devices. This separation prevents lateral movement from compromised user workstations directly into device management interfaces, protecting critical administrative access paths.

Exam trap

Test-takers frequently assume out-of-band networks are designed to speed up administrative throughput or encrypt regular production workloads, missing their core security purpose of stopping lateral attacks.

168
MCQeasy

A junior administrator needs to quickly identify all Windows services that are currently set to start automatically but are not running on a Windows Server 2016. Which PowerShell command should the administrator use?

A.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -ne 'Running'}
B.Get-Service -StartType Automatic | Where-Object {$_.Status -eq 'Stopped'}
C.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -or $_.Status -eq 'Stopped'}
D.Get-Service | Where-Object {$_.StartType -eq 'Automatic' -and $_.Status -eq 'Stopped'}
AnswerA

This command filters services where the StartType is 'Automatic' and the Status is not 'Running'. It directly returns the list of automatic services that are stopped or in another non-running state. The Where-Object cmdlet evaluates each service object, and the condition uses -and to combine both criteria. This is the most straightforward and accurate way to achieve the goal.

Why this answer

To find automatic services that are not running, you must filter by StartType equal to 'Automatic' and Status not equal to 'Running'. The correct command uses Where-Object with -and and -ne to capture all non-running states. This ensures you don't miss services that are paused or in transition.

Exam trap

The trap here is assuming that 'not running' means only 'Stopped' or using -or instead of -and, which broadens the results incorrectly.

169
MCQhard

A government agency uses a defense in depth architecture with strict perimeter firewalls, network segmentation, and endpoint protection. During a red team exercise, attackers gained initial access via a phishing email and then moved laterally by exploiting a misconfigured internal server. The agency wants to improve its ability to detect and respond to such lateral movement. Which control would be most effective to add?

A.Enforcing application whitelisting on all endpoints
B.Increasing the perimeter firewall rule set to block more inbound ports
C.Deploying network-based intrusion detection system (NIDS) sensors on internal network segments
D.Implementing stricter email filtering to prevent phishing emails
AnswerC

NIDS sensors on internal segments monitor east-west traffic for malicious patterns, such as exploit attempts and unusual lateral movement. This directly addresses the gap that allowed attackers to move internally after initial compromise. It adds a detective layer inside the network, complementing perimeter defenses and endpoint controls.

Why this answer

Lateral movement occurs inside the network after initial compromise, so detection requires visibility into internal traffic. NIDS sensors on internal segments can identify exploit attempts, scanning, and unusual communication patterns between hosts. Perimeter and email controls address initial access, while application whitelisting is host-focused and may not detect network-based movement.

Internal NIDS fills the specific gap highlighted by the red team exercise.

Exam trap

The trap here is assuming that strengthening perimeter or email defenses will detect internal lateral movement, when those controls operate at the boundary and do not see east-west traffic.

170
MCQeasy

A security administrator is configuring a Linux server to encrypt a new block device that will store sensitive data. The administrator wants to ensure that data is encrypted at rest and that the encryption key is protected by a passphrase. Which of the following tools is designed specifically for this purpose?

A.eCryptfs
B.OpenSSL
C.dm-crypt with LUKS
D.GnuPG (GPG)
AnswerC

dm-crypt is a Linux kernel subsystem that provides transparent disk encryption, and LUKS (Linux Unified Key Setup) is a standard format for storing key material. Together, they allow encrypting a block device with a passphrase-protected key. LUKS manages multiple passphrases and stores metadata in the device header. This is the standard tool for full disk encryption on Linux.

Why this answer

dm-crypt with LUKS is the standard Linux solution for block device encryption. dm-crypt provides the kernel-level encryption, while LUKS provides a standardized header and key management, allowing multiple passphrases to unlock the encryption key. This directly meets the requirement of encrypting a block device with a passphrase-protected key.

Exam trap

The trap here is confusing file-level encryption tools like GnuPG or eCryptfs with block-level encryption, which requires dm-crypt/LUKS for full disk encryption.

171
MCQhard

A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?

A.Disable macros in Microsoft Office applications by default and only allow signed macros from trusted publishers.
B.Implement a security awareness training program that teaches employees to recognize phishing emails.
C.Deploy an endpoint detection and response (EDR) solution to detect and block malicious macro execution.
D.Configure email filtering to block all emails with macro-enabled attachments.
AnswerA

Disabling macros by default and allowing only signed macros from trusted publishers directly prevents the execution of malicious macros, which was the initial infection vector. This is a technical control that enforces a secure configuration and is highly effective because it blocks the attack technique regardless of user action. It aligns with the principle of least functionality and is a recommended security baseline.

Why this answer

The most effective action is to disable macros by default and allow only signed macros from trusted publishers. This directly prevents the malicious macro from executing, regardless of whether the phishing email reaches the user. It is a technical control that enforces a secure configuration and reduces the attack surface.

While other measures like training, EDR, and email filtering add defense in depth, they are not as reliable in stopping this specific vector. Disabling macros is a best practice recommended by security organizations.

Exam trap

The trap here is choosing a detective or user-dependent control like training or EDR when a preventive technical control that directly blocks the attack technique is available and more effective.

172
Multi-Selecthard

Which TWO of the following actions are primarily restricted by macOS System Integrity Protection (SIP)?

Select 2 answers
A.Modifying files within the /System directory
B.Installing unsigned applications from the internet
C.Loading unsigned kernel extensions (kexts)
D.Accessing user-defined keychain items
E.Encrypting the user home directory
AnswersA, C

The /System directory contains core macOS components that are essential for system stability and security. SIP explicitly prevents the root user from writing to or modifying files in this path, ensuring that core binaries and libraries remain untampered throughout the lifecycle of the operating system.

Why this answer

SIP is a crucial security layer that limits root user capabilities to prevent system-level damage. By restricting modifications to protected system directories and kernel extensions, it effectively hardens the operating system against exploitation. For GSEC professionals, identifying what SIP protects is vital for performing system audits, troubleshooting software installations, and managing secure configurations, as these restrictions often impact how security agents and administrative tools interact with the underlying OS.

Exam trap

Candidates often assume SIP restricts user-space application installation, whereas SIP specifically targets system-level modifications and kernel extensions to prevent deep OS-level compromise.

173
MCQmedium

An administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?

A.Immediately terminate the process using the task manager.
B.Perform a full system backup to an external network share.
C.Isolate the infected host from the network via switch port shutdown.
D.Run a full scan with the local antivirus engine.
AnswerC

Network isolation successfully severs the communication channel between the malware and the attacker's command-and-control server. This containment step halts data exfiltration and remote command execution while leaving the host powered on, allowing for the secure collection of volatile memory and disk images for post-incident forensic investigation.

Why this answer

Isolating the host from the network preserves the integrity of the volatile memory and prevents command-and-control communication. In security operations, containment precedes deep analysis to ensure the adversary cannot execute further malicious actions or delete artifacts. This approach balances the need for forensic readiness with the urgent requirement to stop ongoing lateral movement or data exfiltration, adhering to standard GIAC incident response methodologies regarding host-based threat containment.

Exam trap

Candidates often suggest 'rebooting the host' or 'running a virus scan'. These actions wipe volatile memory, destroying critical forensic evidence before the incident responder can analyze the threat.

174
MCQmedium

A hospital runs a VMware vSphere cluster with several ESXi 8 hosts. The security team discovers that an attacker who compromised one guest VM was able to read memory contents belonging to a different VM on the same host. Which vSphere setting should have been enabled to prevent this cross-VM memory disclosure at the hardware level?

A.Enable Encrypted vMotion on the VMkernel adapter.
B.Configure a vSphere Standard Switch with VLAN tagging for each VM.
C.Set the VM's isolation.tools.copy.disable parameter to TRUE.
D.Enable CPU virtualization-based security features such as AMD SEV-ES or Intel TDX for the VM.
AnswerD

Confidential computing extensions like AMD SEV-ES and Intel TDX encrypt guest memory in hardware so the hypervisor and other VMs cannot read it. Enabling these for the affected VM would prevent the compromised guest from reading memory belonging to a different VM, directly mitigating the cross-VM memory disclosure described.

Why this answer

Hardware-based confidential computing features such as AMD SEV-ES and Intel TDX encrypt VM memory so that even the hypervisor and co-resident VMs cannot read it. This directly addresses the cross-VM memory disclosure, whereas the other options address migration encryption, network segmentation, or console clipboard controls, none of which isolate physical memory between guests on the same ESXi host.

Exam trap

The trap here is assuming that any vSphere hardening feature, such as encrypted vMotion or VLAN tagging, will stop a local cross-VM memory read when only hardware memory encryption extensions address that specific threat.

175
MCQmedium

A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?

A.Perform a phased Nmap discovery using host discovery first, then targeted service/version detection with conservative timing options such as -T2 and limited port ranges, documenting results before any exploitation phase.
B.Skip active scanning entirely and rely only on the client's existing asset inventory spreadsheet, then begin exploitation attempts against the listed hosts.
C.Run a full Nmap scan with -sS and no timing adjustments across the entire /16, then immediately launch the exploitation framework against every discovered service.
D.Use a single aggressive Nmap scan with -T5 and the default top-1000 ports, then treat every open port as an exploitable finding in the final report.
AnswerA

A phased approach separates live-host discovery from service enumeration, letting the tester narrow the target set and apply conservative timing and port scope. Version detection with controlled timing reduces the chance of overwhelming fragile services, directly honoring the no-denial-of-service constraint. Documenting results before exploitation supports repeatable planning and keeps later phases tied to validated findings rather than assumptions.

Why this answer

The phased approach with host discovery followed by conservative service/version detection controls packet volume and timing, which is what keeps a scan from disrupting production services. Narrowing targets before enumeration also makes later exploitation planning more accurate. Aggressive timing, immediate exploitation, or relying on stale inventory all conflict with either the safety constraint or the objective of verifying live services.

Exam trap

The trap here is assuming that a faster or broader scan always produces better assessment data, when in a production environment the engagement's safety constraints make scan pacing and scope the deciding factors.

176
MCQeasy

Which security control is most effective at preventing the execution of unauthorized or malicious software by enforcing a 'deny-by-default' policy on a workstation?

A.Endpoint Detection and Response (EDR) agents.
B.Next-Generation Antivirus (NGAV) with behavioral analysis.
C.Application Whitelisting (e.g., AppLocker or WDAC).
D.Host-based Intrusion Prevention System (HIPS).
AnswerC

Application whitelisting explicitly restricts execution to only approved binaries, scripts, and installers. By implementing a default-deny policy, it ensures that any unauthorized or malicious software—regardless of whether it is known to security vendors—will be blocked from executing on the host, providing a robust security posture.

Why this answer

Application whitelisting (or Application Control) prevents any program from running unless it is explicitly permitted by a defined policy. This is vastly superior to blacklisting, which can only block known threats. In a professional environment, this controls the execution environment, significantly reducing the attack surface by ensuring that only vetted and approved binaries, scripts, and installers can run, effectively mitigating zero-day threats and unauthorized utility usage.

Exam trap

Candidates often choose 'Antivirus' or 'Endpoint Detection and Response (EDR)' because they are common tools, forgetting that these are often signature-based and do not inherently implement a strict 'deny-by-default' execution policy.

177
MCQhard

A penetration tester is assessing a web application and finds that user input is reflected into an HTML page without encoding. The tester wants to demonstrate that an attacker could steal a victim's session cookie by injecting a script that sends the cookie to an external server. Which mitigation, when implemented by the developers, most directly prevents this specific cookie theft even if the input reflection remains?

A.Set the session cookie with the HttpOnly attribute.
B.Add the Secure attribute to the session cookie.
C.Enable Content Security Policy with a strict script-src directive.
D.Implement output encoding for all user-supplied data.
AnswerA

The HttpOnly attribute prevents client-side scripts from accessing the cookie through document.cookie, so even a successful reflected script injection cannot read and exfiltrate the session cookie. This directly neutralizes the described theft technique while leaving the reflection bug in place. It is a targeted, server-side cookie attribute that requires no changes to input handling and is the most direct mitigation for script-based session cookie theft.

Why this answer

The HttpOnly attribute makes the session cookie inaccessible to client-side scripts, so a reflected script injection cannot read or exfiltrate it. This directly counters the described attack even though the reflection vulnerability remains. While output encoding would fix the root cause and a strict Content Security Policy would reduce script execution, the question asks for the most direct prevention of cookie theft given the reflection, and HttpOnly is that control.

Exam trap

The trap here is choosing the root-cause fix (output encoding) when the question explicitly asks for the control that protects the cookie even if the reflection remains.

178
MCQeasy

A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?

A.netstat -an
B.ipconfig /all
C.nslookup app.internal.example.com
D.tracert app.internal.example.com
AnswerC

nslookup queries DNS servers directly and reports the resolved address or an error, which quickly confirms whether the configured resolver can resolve the internal hostname. Because the application works by IP, the failure is isolated to name resolution, and this command tests exactly that path. It is available on Windows, Linux, and macOS and is the appropriate first diagnostic step in this scenario.

Why this answer

Because the application is reachable by IP but not by hostname, the fault lies in name resolution rather than connectivity or routing. Querying DNS directly with nslookup tests whether the configured resolver returns the correct address or an error, which isolates the problem. Other commands either require successful resolution first or inspect unrelated local state.

Exam trap

The trap here is reaching for a connectivity tool such as tracert or a configuration display like ipconfig /all, when the symptom specifically points to a name-resolution failure that only a DNS query can confirm.

179
MCQmedium

An organization is implementing a Windows Defender Application Control (WDAC) policy to block unauthorized executables on Windows 10 endpoints. The security team wants to ensure that only signed binaries from trusted publishers are allowed to run, but they also need to allow a specific in-house application that is not signed. What is the most appropriate approach?

A.Use a hash rule to allow the specific unsigned application by its file hash.
B.Create a publisher rule for the in-house application's certificate, even though it is not signed.
C.Set WDAC to audit mode so that the unsigned application can run without being blocked.
D.Disable WDAC enforcement for the entire endpoint to allow the unsigned application to run.
AnswerA

WDAC supports hash rules, which allow executables based on their unique file hash. This is ideal for unsigned applications that need to be whitelisted. The hash ensures that only that exact file is allowed, and any modification changes the hash, preventing tampering. This approach maintains a strong security posture while permitting the necessary application.

Why this answer

WDAC allows exceptions for specific files using hash rules. This is the most appropriate method to permit an unsigned application while still enforcing the policy for all other executables. Hash rules are precise and secure because they tie the exception to the exact file content.

Disabling WDAC, using publisher rules without a signature, or switching to audit mode would either weaken security or not work.

Exam trap

The trap here is thinking that publisher rules can be used for unsigned applications, but they require a valid signature.

180
Multi-Selectmedium

A security architect is hardening an organization's network infrastructure against reconnaissance and layer-2 attacks. Which TWO actions should the engineering team take to mitigate common switch-based vulnerabilities? (Choose TWO)

Select 2 answers
A.Disabling dynamic trunking protocol on all user-facing access layer switch ports.
B.Enabling dynamic ARP inspection across all core routing interfaces without configuring DHCP snooping bindings.
C.Configuring the native VLAN on all trunk ports to use a dedicated, unused VLAN ID rather than the default VLAN 1.
D.Routing all broadcast domain traffic through unmanaged Layer-1 repeating hubs to obscure physical topology.
E.Installing public-facing web servers directly into the native management VLAN of the core enterprise switches.
AnswersA, C

Dynamic trunking protocol allows switches to automatically negotiate trunk links with connected devices. Disabling this feature on user-facing access ports prevents malicious actors from injecting crafted DTP frames to force a port into a trunking state and bypass VLAN boundaries.

Why this answer

Mitigating layer-2 vulnerabilities requires disabling dynamic trunking protocol auto-negotiation and explicitly setting native VLAN identifiers to unused, isolated values. Disabling dynamic trunk negotiation stops rogue switches from forming trunk links, while changing the native VLAN prevents VLAN hopping attacks that exploit un-tagged traffic handling on trunk links.

Exam trap

Candidates frequently select generic port security or spanning-tree options instead of focusing on the specific layer-2 mechanisms like DTP and native VLAN mismatches targeted by the question.

181
MCQmedium

Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?

A.SQL Injection; Containment
B.Cross-Site Scripting; Identification
C.Cross-Site Request Forgery; Eradication
D.Buffer Overflow; Preparation
AnswerB

The log displays an XSS payload injected into a form field, which the framework correctly blocked. This activity represents an active probe by an attacker. It must move to the Identification phase to determine the extent of the scanning or exploitation attempts being conducted against the web application.

Why this answer

The exhibit shows a Cross-Site Scripting (XSS) attempt blocked by the application's input validation layer. This should trigger the Identification phase of the incident response lifecycle. Even though the attack was blocked, it indicates an attacker is actively probing the application for vulnerabilities.

Early detection allows the team to block the source IP and verify if other, more successful, attempts were made against the infrastructure.

Exam trap

Candidates frequently confuse the 'Identification' phase with 'Containment'. They assume that because the attack was blocked, the incident is closed, overlooking that identification is necessary to assess the threat actor's intent.

182
MCQhard

A multinational corporation is aligning its incident response program with the CIS Critical Security Controls. They are focusing on CIS Control 17: Incident Response Management. Which of the following activities best demonstrates the establishment of a formal incident response process as required by this control?

A.Establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures.
B.Designating a single individual as the incident response coordinator without a formal team.
C.Conducting an annual tabletop exercise without updating the incident response plan based on findings.
D.Purchasing an incident response automation tool to streamline handling of security incidents.
AnswerA

Safeguard 17.1 explicitly requires establishing and maintaining a documented incident response plan. This plan must define roles, responsibilities, and communication procedures. It is the cornerstone of CIS Control 17. A documented plan ensures that all stakeholders know their duties during an incident, facilitating a coordinated and effective response. This is the best demonstration of a formal process.

Why this answer

CIS Control 17 requires establishing and maintaining a documented incident response plan that defines roles, responsibilities, and communication procedures. This formal documentation is the foundation of the incident response process. While tools, exercises, and designated personnel are valuable, they are not sufficient without a documented plan that guides the overall response effort.

Exam trap

The trap here is focusing on tools or exercises as the primary requirement, while overlooking the need for a documented incident response plan that defines roles and communication.

183
MCQmedium

A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?

A.ARP cache poisoning
B.VLAN hopping
C.DHCP starvation
D.MAC flooding
AnswerA

ARP cache poisoning involves sending forged ARP replies to associate an attacker's MAC address with a legitimate IP, such as the default gateway. This allows the attacker to intercept or redirect traffic. In this scenario, the unsolicited replies with a mismatched MAC for the gateway IP are a classic indicator of ARP spoofing, enabling man-in-the-middle or denial-of-service conditions on the LAN.

Why this answer

Unsolicited ARP replies that incorrectly map the default gateway's IP to an attacker-controlled MAC address are the hallmark of ARP cache poisoning. This attack poisons the ARP cache of hosts, redirecting their traffic through the attacker for interception or disruption. The mismatch between the legitimate gateway MAC and the claimed MAC confirms the malicious manipulation.

Exam trap

The trap here is confusing ARP cache poisoning with MAC flooding, but MAC flooding targets switch CAM tables, not host ARP caches, and does not produce forged gateway mappings.

184
MCQmedium

An organization needs to encrypt a database of PII. The requirements state that the encryption must be reversible by authorized staff and provide data integrity. Which implementation should the security engineer recommend?

A.Use SHA-256 hashing for all database fields.
B.Implement AES-256 in GCM mode.
C.Use RSA-4096 for encrypting large datasets.
D.Apply XOR-based encryption with a static global key.
AnswerB

AES-256 in GCM mode offers high-speed, symmetric encryption that ensures confidentiality while simultaneously providing integrity through an authentication tag. This approach satisfies the dual requirements of reversibility for authorized users and protection against data tampering, which is the gold standard for protecting sensitive database records in modern systems.

Why this answer

Using AES-256 in GCM mode provides both confidentiality and authenticity. Symmetric encryption is appropriate for database encryption where authorized entities hold the decryption keys. GCM mode is preferred because it acts as an Authenticated Encryption with Associated Data (AEAD) algorithm, preventing unauthorized modification of the ciphertext.

This is critical for database security, where verifying that data has not been tampered with is as important as preventing unauthorized disclosure of the stored information.

Exam trap

Candidates often select asymmetric encryption or simple hashing. They fail to realize that database encryption requires symmetric performance and that GCM provides the necessary integrity checking for data.

185
MCQhard

A security researcher is evaluating the susceptibility of a WPA3-Personal network to offline dictionary attacks. Which statement accurately describes the resistance provided by WPA3-SAE compared to WPA2-PSK?

A.WPA3-SAE still allows offline dictionary attacks but requires more computational effort due to stronger encryption.
B.WPA3-SAE requires a captive portal to prevent offline attacks, as it does not encrypt management frames.
C.WPA3-SAE prevents offline dictionary attacks by using a simultaneous authentication of equals handshake that does not expose a crackable hash.
D.WPA3-SAE uses the same 4-way handshake as WPA2-PSK but with a longer key, making offline attacks infeasible.
AnswerC

WPA3-SAE uses a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline brute-force because the exchange does not reveal a password-derived hash that can be tested without interacting with the AP. This is a key improvement over WPA2-PSK, which is vulnerable to offline cracking.

Why this answer

WPA3-SAE employs the Dragonfly handshake, which provides forward secrecy and prevents offline dictionary attacks by ensuring that the password is not exposed in a crackable form. An attacker must interact with the AP for each guess, making brute-force impractical. WPA2-PSK's 4-way handshake exposes a hash that can be cracked offline.

The other options mischaracterize SAE's design or confuse it with unrelated features.

Exam trap

The trap here is thinking that WPA3-SAE merely strengthens encryption or lengthens keys, when its core advantage is the Dragonfly handshake that eliminates the offline crackable hash.

186
MCQeasy

A medium-sized company's Windows workstations are being infected by malicious macro documents delivered as .docm email attachments. Employees routinely open these attachments because the macros appear to come from a trusted internal sender. The security team wants to stop the macro execution with the least disruption to legitimate business macros, which are used only by the finance department. Which mitigation should the team implement first?

A.Enable Microsoft Defender Application Guard for Office to open untrusted documents in an isolated container.
B.Configure an email gateway rule to strip all .docm attachments and quarantine them for administrator review.
C.Use Group Policy to set the Microsoft Office macro notification setting to 'Disable all macros except digitally signed macros' and distribute a trusted publisher certificate to finance.
D.Deploy an endpoint detection and response agent and create a detection rule that alerts when WINWORD.EXE spawns a child process.
AnswerC

This policy blocks unsigned macros for all users while permitting finance's signed macros, directly addressing the infection vector with minimal business impact. Trusted publisher certificates let finance macros run without prompts, and all other unsigned macros are silently blocked. This is the standard Group Policy control for exactly this scenario and does not require third-party tooling or network changes, making it the correct first step.

Why this answer

The correct control is a Group Policy macro setting that disables unsigned macros while allowing digitally signed macros, with a trusted publisher certificate deployed to finance. This blocks the malicious macro execution path for nearly all users, preserves the legitimate finance macros, and requires no changes to email flow or third-party tools. It is the least disruptive, targeted mitigation for macro-borne malware in a Windows Office environment.

Exam trap

The trap here is assuming that email attachment filtering alone solves macro malware, when the execution decision actually happens inside the Office application and must be controlled by macro policy.

187
MCQhard

A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?

A./etc/hosts
B./etc/crontab and the /etc/cron.* directories
C./var/log/auth.log
D./etc/passwd
AnswerB

The /etc/crontab file and the /etc/cron.* directories contain system-wide scheduled tasks that run automatically at specified intervals or at boot. Attackers commonly add entries here to re-establish access after a reboot. Reviewing these locations is a primary step in identifying persistence via scheduled tasks. Other cron locations such as user crontabs also matter, but the system-wide files are the first place to check for reboot-persistent jobs.

Why this answer

System-wide cron files and directories are the primary location for scheduled tasks on Linux. Attackers frequently add entries to /etc/crontab or /etc/cron.* to run malicious commands at boot or regular intervals, ensuring persistence across reboots. Examining these files first aligns with the goal of identifying how the attacker maintains access after a restart.

Exam trap

The trap here is focusing on user account files or logs, when the question specifically asks for scheduled tasks that run automatically.

188
MCQmedium

Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?

A.The endpoint is vulnerable to root-level system file modification.
B.The endpoint's kernel integrity protections are actively enforced.
C.The disk encryption configuration is currently failing.
D.The device has been successfully compromised by a kernel rootkit.
AnswerB

When SIP status is reported as enabled, the kernel is protected from unsigned extensions and unauthorized modifications. This is the intended behavior for a secure macOS deployment, ensuring that only trusted components can execute at the lowest levels of the operating system, thereby mitigating risks from malicious drivers.

Why this answer

The output confirms that System Integrity Protection is currently active on the host. This status indicates that the core OS protections are enforced, preventing unauthorized modification of system-protected locations and restricted kernel operations. In a GSEC context, confirming the status of SIP is a primary validation step during an incident response or security audit, as disabling SIP is a common technique used by attackers to gain persistence and evade detection on macOS.

Exam trap

Candidates often confuse SIP status output with other security features like Gatekeeper or FileVault, or they incorrectly assume that 'active' status implies the system is currently free of malware.

189
MCQhard

A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?

A.A DNS amplification attack, where spoofed queries generate large responses aimed at a victim.
B.DNS cache poisoning, where forged responses insert malicious records into a resolver's cache.
C.DNS tunneling, where data and commands are encoded into DNS queries and responses to create a covert channel.
D.A zone transfer abuse, where the attacker pulls the entire DNS zone from an authoritative server.
AnswerC

DNS tunneling encodes arbitrary payloads into query names and response records, using the resolver as a transport to an attacker-controlled authoritative server. Long, high-entropy subdomain labels and a high volume of queries to one domain are classic indicators. Because DNS is rarely blocked, this technique lets a compromised host exfiltrate data and receive commands while blending into normal resolution traffic.

Why this answer

Encoding data into DNS query names and response records creates a covert channel known as DNS tunneling. High-entropy subdomain labels and a sustained query volume toward one external domain are the hallmarks. The resolver forwards queries to the attacker's authoritative server, which returns encoded responses.

This differs from zone transfers, cache poisoning, and amplification, which have distinct traffic signatures and objectives.

Exam trap

The trap here is labeling any abusive DNS traffic as cache poisoning or amplification when the bidirectional, encoded query pattern uniquely indicates tunneling.

190
MCQhard

A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?

A.Deploy a TLS-based VPN portal with multi-factor authentication, server certificates, and HSTS enforced.
B.Publish the internal application through a reverse proxy that uses basic authentication over HTTPS.
C.Deploy an IPsec VPN that requires a client certificate issued to each device.
D.Deploy an IPsec VPN with pre-shared keys distributed to each employee's device.
AnswerA

A TLS-based portal authenticates the server with a certificate the client validates, and multi-factor authentication protects against stolen passwords. HSTS forces browsers to use HTTPS and prevents downgrade or SSL-stripping attacks. Because the client only needs to trust the server certificate and complete MFA, no client certificate is required on the personal device, satisfying all stated constraints.

Why this answer

The design must authenticate the server, resist credential theft, resist man-in-the-middle, and avoid client certificates on personal devices. A TLS-based VPN portal with MFA and server certificates meets all of these: the client validates the server certificate, MFA blocks stolen-password reuse, and HSTS prevents downgrade attacks. The other options either require client certificates, rely on weak shared secrets, or use reusable basic credentials.

Exam trap

The trap here is equating strong authentication with client certificates, when server-certificate validation plus multi-factor authentication can meet the requirement without provisioning anything on the personal device.

191
MCQmedium

Refer to the exhibit. A network administrator configured port security on a switch interface to protect against unauthorized device connections. Based on the provided configuration snippet, what action will the switch take if a third device with an unknown MAC address connects to this port?

A.The switch will forward the third device's traffic while generating an alert log entry to the central syslog server without dropping packets.
B.The switch will immediately transition the interface into an error-disabled state and shut down port operations.
C.The switch will drop packets originating from the third device while keeping the physical port in an active operational state.
D.The switch will temporarily quarantine the third device in a restricted guest VLAN while awaiting administrator approval.
AnswerB

Configuring port security with violation shutdown instructs the switch to disable the interface immediately upon detecting more unique MAC addresses than permitted. This robust defense prevents unauthorized hardware from maintaining connectivity to the access network.

Why this answer

When port security is configured with a maximum limit of two MAC addresses and a violation mode of shutdown, the switch immediately disables the interface the moment a third unique MAC address attempts to communicate. The port enters an error-disabled state, dropping all traffic until an administrator manually resets the interface or configures an automatic recovery timer.

Exam trap

Candidates often assume the switch will only block the third device. They forget that the 'shutdown' violation mode forces the entire port into an error-disabled state, stopping all traffic.

192
Multi-Selectmedium

Which THREE of the following are considered best practices for auditing Windows event logs to enhance security monitoring?

Select 3 answers
A.Centralize logs to a SIEM for long-term storage
B.Increase maximum log size to prevent log overwriting
C.Audit every single file access on the system
D.Enable auditing of process creation and logons
E.Require domain admins to clear logs daily
AnswersA, B, D

Centralizing logs is crucial because local logs can be cleared by an attacker to hide their tracks. A SIEM ensures that logs are stored securely off-host, allowing for correlation and analysis that would be impossible if limited only to local disk space.

Why this answer

Effective log auditing relies on consistency, central collection, and meaningful alerting. By setting a large log size, ensuring remote aggregation, and auditing critical security-related events, organizations move from reactive to proactive monitoring. These practices are essential for ensuring that evidence is preserved during an incident and that alerts are generated for high-value security events before they are rotated out of the local logs.

Exam trap

Candidates often suggest auditing everything, which leads to log saturation and performance issues. They fail to understand that effective auditing focuses on specific, high-value security events like process creation.

193
MCQmedium

A security analyst is investigating a potential insider threat. The SIEM has ingested logs from multiple sources, including Windows Security logs, Linux auditd, and VPN concentrators. The analyst needs to determine which user account accessed a sensitive file server at 2:00 AM. Which log source and field should the analyst query to identify the user account that initiated the file access?

A.VPN concentrator logs with the UserName field and the AssignedIP field.
B.Linux auditd logs with the key field set to "file_access" and the uid field.
C.Windows Security Event ID 4663 (An attempt was made to access an object) with the SubjectUserName field.
D.Windows Security Event ID 4624 (An account was successfully logged on) with the TargetUserName field.
AnswerC

Event ID 4663 is generated when an object (like a file) is accessed, provided object access auditing is enabled. The SubjectUserName field identifies the account that attempted the access. By filtering for the file server's object name and the timestamp, the analyst can pinpoint the user. This event is specifically designed for file access auditing, making it the most direct source for this scenario.

Why this answer

To identify the user account that accessed a sensitive file, the analyst should look for object access auditing events. Windows Security Event ID 4663 is generated when an object is accessed and includes the SubjectUserName, which identifies the account. Filtering by the file server and timestamp yields the specific user.

Other log sources either do not record file-level access or provide only indirect information.

Exam trap

The trap here is confusing logon events (4624) with object access events (4663), leading to the wrong event ID for file access auditing.

194
MCQeasy

A security analyst is reviewing Windows event logs to detect suspicious service installations. The analyst notices Event ID 7045 in the System log, indicating a new service was installed. The service name is 'UpdaterSvc', and the image path points to a binary in a user's temp folder. The analyst wants to determine the most likely security implication of this event. Which of the following best describes the risk?

A.The service represents a potential persistence mechanism used by an attacker to maintain access to the system.
B.The event indicates a driver installation, which could cause a blue screen of death.
C.The service is likely a legitimate Windows update service, and the event can be ignored.
D.The service installation is a sign of a Windows Update failure, and the system should be rolled back.
AnswerA

Event ID 7045 indicates a new service was installed. Attackers often create services to achieve persistence, as services can be configured to start automatically at boot and run with high privileges. A binary in a user's temp folder is a red flag because legitimate services rarely reside there. This suggests the service was installed by an attacker or malicious software. Investigating the binary, its hash, and the installing user is critical. This option correctly identifies the risk of persistence, which is a common tactic in cyber attacks.

Why this answer

Event ID 7045 in the System log indicates a new service was installed. When the service binary is located in a user's temp folder, it strongly suggests malicious activity, as legitimate services are installed in protected system directories. Attackers use services for persistence because they can start automatically and run with elevated privileges.

The correct response is to treat this as a potential compromise and investigate further. The other options misinterpret the event or underestimate the risk.

Exam trap

The trap here is assuming that any service installation event is benign or related to updates, when the location of the binary is a critical indicator of compromise.

195
MCQeasy

An administrator wants to prevent unauthorized modification of Windows Services. Which tool allows for the centralized management of service startup types and logon accounts across multiple domain-joined systems?

A.Task Scheduler
B.Services.msc
C.Group Policy Management Console (GPMC)
D.Local Security Policy (secpol.msc)
AnswerC

GPMC provides the interface to define and deploy Group Policy Objects. These objects allow administrators to centrally configure service security, startup behaviors, and account permissions across the entire Active Directory domain, ensuring a uniform and auditable security baseline for all managed Windows services and host systems.

Why this answer

Group Policy Objects (GPO) are the standard mechanism in Windows environments to enforce security configurations, including service management, across an entire fleet. Centralized control ensures that security policies are applied consistently, preventing configuration drift and unauthorized changes that could be exploited by attackers. By leveraging GPOs, administrators can maintain a hardened baseline, which is a foundational requirement for both GIAC compliance standards and general enterprise cybersecurity best practices.

Exam trap

Students mistakenly choose local security policies (secpol.msc) or task scheduler utilities, forgetting that centralized multi-system management requires the Group Policy Management Console.

196
MCQmedium

Which password management practice best minimizes the impact of a credential stuffing attack?

A.Mandating password changes every 30 days
B.Requiring a minimum password length of 8 characters
C.Enforcing unique passwords per service
D.Disabling account lockout after failed attempts
AnswerC

Unique passwords ensure that even if one account's credentials are breached in a data leak, the attacker cannot use those same credentials to access other platforms. This containment strategy isolates the impact of a breach and prevents the automated success typically associated with large-scale credential stuffing campaigns against modern web services.

Why this answer

Credential stuffing relies on users reusing the same passwords across multiple services. By enforcing unique, complex passwords for every single account, users ensure that a compromise at one service does not lead to a cascade of compromises elsewhere. This is the single most effective defense against automated attacks that attempt to use leaked database dumps to gain unauthorized access to other unrelated accounts held by the same user.

Exam trap

Candidates often select 'frequent password changes' as the answer, failing to realize that frequent changes do not prevent credential stuffing if the same password is used everywhere.

197
MCQmedium

A financial firm is architecting a new cardholder data environment (CDE) that must comply with PCI DSS segmentation requirements. The security team proposes using a single internal VLAN with host-based firewalls on each server to isolate CDE systems from corporate desktops. The auditor rejects this design. Which approach BEST meets the requirement for defensible network segmentation?

A.Place CDE systems in a dedicated VLAN and enforce inter-VLAN access control with a stateful firewall that permits only required flows from corporate networks.
B.Keep all systems in one VLAN but require 802.1X authentication for every desktop before it can send traffic to CDE servers.
C.Implement private VLANs (PVLANs) on the access switches so that CDE servers are in an isolated secondary VLAN and corporate desktops are in a community VLAN.
D.Deploy host-based firewalls on each CDE server and configure them to allow only connections from the corporate desktop subnet.
AnswerA

This isolates the CDE at Layer 2 and enforces a policy enforcement point at Layer 3/4, which is the standard defensible segmentation for PCI DSS. A stateful firewall provides explicit allow rules, logging, and the ability to prove that no unauthorized traffic can reach cardholder systems from corporate desktops.

Why this answer

A dedicated VLAN combined with a stateful firewall creates a clear enforcement boundary where only explicitly permitted flows can enter the CDE. This design provides the isolation, logging, and policy control that PCI DSS auditors expect. Host-based controls alone cannot substitute for network segmentation because they do not prevent lateral movement across the flat network.

Exam trap

The trap here is assuming that host-based firewalls or 802.1X authentication can replace network segmentation, when they only protect individual hosts and do not create an auditable isolation boundary.

198
MCQmedium

A security engineer is evaluating a container runtime for a production Kubernetes cluster. The requirement is that the runtime must not share the host kernel with containers, providing stronger isolation than standard runc-based containers. Which of the following runtimes best satisfies this requirement?

A.runc with user namespaces enabled
B.CRI-O with the default runtime configured for SELinux enforcement
C.containerd configured with the default runc shim
D.Kata Containers, which runs each pod inside a lightweight virtual machine
AnswerD

Kata Containers launches each pod in a lightweight VM with its own guest kernel, so container workloads do not share the host kernel. This provides hardware-virtualization-based isolation that satisfies the requirement. A kernel exploit in the guest does not automatically compromise the host, making Kata the correct choice for stronger isolation.

Why this answer

Kata Containers runs each pod in a lightweight virtual machine with its own guest kernel, so workloads do not share the host kernel. This hardware-virtualization-based isolation provides a stronger boundary than runc, containerd with runc, or CRI-O with SELinux, all of which share the host kernel and are therefore vulnerable to kernel-level escapes.

Exam trap

The trap here is equating hardening features like user namespaces or SELinux with kernel isolation, when only VM-based runtimes such as Kata provide a separate kernel per pod.

199
MCQhard

An analyst is examining a Linux server suspected of compromise. The analyst runs a script that lists open network connections, running processes, and loaded kernel modules, but does not copy the binaries to external media. Which principle is the analyst applying?

A.Chain of custody, by documenting each piece of evidence collected.
B.Order of volatility, by collecting live system state before it changes.
C.Least privilege, by limiting the analyst's access to system resources.
D.Defense in depth, by using multiple tools to examine the system.
AnswerB

The analyst is capturing volatile data such as network connections, processes, and kernel modules while the system is live, before it changes or is lost. This directly follows the order of volatility principle, which prioritizes the most perishable evidence first. Running the script before copying binaries reflects that prioritization, making this the correct principle.

Why this answer

The order of volatility directs responders to collect the most perishable evidence first, such as network connections, running processes, and kernel modules, before they change or disappear. By gathering this live state before copying static binaries, the analyst is prioritizing volatile data. Chain of custody, least privilege, and defense in depth address different concerns and do not describe this collection sequence.

Exam trap

The trap here is assuming that copying binaries to external media is the first step, when volatile live state must be captured before less perishable artifacts.

200
MCQmedium

A security administrator is configuring a Linux server and needs to enforce that all user passwords are hashed with a strong, salted algorithm. Which file should the administrator edit to set the default password hashing algorithm for new passwords?

A./etc/pam.d/common-password
B./etc/passwd
C./etc/shadow
D./etc/login.defs
AnswerD

/etc/login.defs contains configuration settings for the shadow password suite, including the ENCRYPT_METHOD variable, which defines the default password hashing algorithm (e.g., SHA512). Editing this file allows the administrator to enforce a strong, salted algorithm for new passwords. This is the correct file because it controls system-wide password policy defaults.

Why this answer

The /etc/login.defs file contains the ENCRYPT_METHOD setting, which specifies the default password hashing algorithm for new passwords on many Linux distributions. Editing this file allows the administrator to enforce a strong, salted algorithm like SHA512. While /etc/shadow stores hashes and PAM configures authentication, the default algorithm is set in login.defs.

Therefore, this is the correct file to edit.

Exam trap

The trap here is assuming that the password hash file (/etc/shadow) or PAM configuration is where the default algorithm is set, when it is actually in /etc/login.defs.

201
MCQeasy

A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?

A.Key encapsulation, so that the long-term secret directly encrypts each session key and guarantees confidentiality of the exchange.
B.Collision resistance, so that two different sessions cannot produce the same derived key material during the handshake.
C.Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.
D.Non-repudiation, so that each VPN endpoint can prove it participated in the session and cannot deny sending traffic.
AnswerC

Perfect forward secrecy derives each session key from ephemeral values that are discarded after the exchange, so a later compromise of a session key or long-term secret cannot reconstruct other sessions' keys. This directly satisfies the requirement that no session key reveal another or the long-term authentication secret.

Why this answer

Perfect forward secrecy uses ephemeral key agreement such as Diffie-Hellman with per-session values, so the long-term authentication secret never encrypts session keys directly. Even if one session key is later compromised, the ephemeral secrets needed to derive other sessions have been erased, and the long-term secret remains protected.

Exam trap

The trap here is confusing confidentiality of the handshake with forward secrecy, assuming any encrypted key exchange prevents one compromised session key from affecting others when only ephemeral, discarded secrets do.

202
MCQhard

A security engineer is hardening a Windows Server 2019 domain controller. The organization wants to ensure that all service accounts used by critical services are managed automatically, with password rotation handled by Active Directory, and that the password is not stored locally on the server. Which of the following should the engineer implement?

A.Use virtual accounts for each service.
B.Create standard domain user accounts and configure them with a long, complex password that never expires.
C.Configure each service to use a standalone Managed Service Account (sMSA).
D.Implement Group Managed Service Accounts (gMSAs) for the services.
AnswerD

Group Managed Service Accounts (gMSAs) are domain accounts whose passwords are managed by Active Directory and rotated automatically every 30 days. They can be used across multiple servers, and the password is not stored locally; instead, the Key Distribution Service (KDS) root key is used to derive the password. This meets all the stated requirements.

Why this answer

Group Managed Service Accounts (gMSAs) are designed for automatic password management across multiple servers. Active Directory manages the password, rotating it every 30 days, and the password is not stored locally. This satisfies the need for domain-wide service accounts with no local password storage, unlike sMSAs, virtual accounts, or standard user accounts.

Exam trap

The trap here is confusing standalone Managed Service Accounts (sMSAs) with group Managed Service Accounts (gMSAs); sMSAs are limited to a single server and do not support multi-server scenarios or automatic rotation across servers.

203
MCQhard

A security administrator needs to ensure that all Windows 10 workstations in a domain automatically forward their security event logs to a central collector to prevent tampering and enable correlation. The organization uses Group Policy. Which of the following should the administrator configure?

A.Enable the "Audit: Force audit policy subcategory settings" policy and set the Security log to archive when full.
B.Deploy a custom PowerShell script via Group Policy that runs at startup to copy the Security.evtx file to a network share.
C.Enable "Windows Event Forwarding" via the Group Policy setting "Configure target Subscription Manager" under Computer Configuration > Administrative Templates > Windows Components > Event Forwarding.
D.Configure the "Maximum Log Size" for the Security log to a large value and enable "Overwrite events as needed".
AnswerC

This Group Policy setting configures the source computers to forward events to a specific collector. It specifies the collector's FQDN and the subscription manager, enabling automatic forwarding of security events. This is the correct method to centrally collect logs from many workstations without manual configuration on each machine, and it supports filtering and scalability for enterprise environments.

Why this answer

Windows Event Forwarding (WEF) is the native mechanism for collecting events from multiple computers. The Group Policy setting "Configure target Subscription Manager" tells source computers where to send events. The collector then uses subscriptions to filter and store events.

This approach is scalable, secure, and supports real-time forwarding. It also allows the collector to use a dedicated service account and can be configured to use HTTPS for encryption, preventing tampering and enabling centralized analysis.

Exam trap

The trap here is assuming that increasing local log size or copying log files manually achieves centralization, when the exam expects knowledge of the built-in Windows Event Forwarding feature.

204
MCQeasy

A junior administrator needs to determine the default gateway configured on a Linux server to troubleshoot outbound connectivity. Which command will display the routing table and show the default route?

A.ip route show
B.netstat -tuln
C.ss -s
D.ifconfig -a
AnswerA

The 'ip route show' command displays the kernel routing table, including the default route typically marked with 'default via'. This directly answers the administrator's need to identify the default gateway. It is the modern replacement for the deprecated 'route' command and works consistently across current Linux distributions.

Why this answer

To view the default gateway, the administrator should inspect the routing table. The 'ip route show' command outputs all routes, including the default route that specifies the gateway via which packets are sent when no other route matches. Interface configuration and socket statistics tools do not expose routing information, so they cannot answer the question.

Exam trap

The trap here is confusing interface configuration tools like ifconfig with routing table tools, even though both relate to networking.

205
MCQhard

A Linux server has the setuid bit set on /usr/bin/passwd. A security engineer notices that a custom binary /opt/tools/backup_tool also has the setuid bit set and is owned by root. The engineer wants to determine whether executing backup_tool will run with root privileges regardless of which user invokes it. Which of the following is the most accurate statement about how the setuid bit affects process credentials on Linux?

A.The process runs with the effective UID of the file owner only if the binary is also executable by the invoking user; otherwise the kernel silently falls back to the invoking user's UID.
B.The setuid bit is ignored on Linux unless the filesystem is mounted with the suid option, so the behavior depends entirely on the mount options of the filesystem holding the binary.
C.The process runs with the effective UID of the file owner, but the real UID remains that of the invoking user, and the saved set-user-ID is set to the file owner's UID.
D.The process runs with the real UID, effective UID, and saved set-user-ID all set to the file owner's UID, so the invoking user's identity is completely lost to the kernel.
AnswerC

When a setuid program is executed, the kernel sets the process's effective UID to the file owner's UID, while the real UID stays as the invoking user's UID. The saved set-user-ID is also set to the file owner's UID, allowing the process to drop and later regain the effective privilege. This is exactly how /usr/bin/passwd can write to /etc/shadow while a normal user runs it.

Why this answer

Executing a setuid binary causes the kernel to set the process's effective UID to the file owner's UID while preserving the real UID of the invoking user. The saved set-user-ID is also set to the file owner's UID, which lets the program temporarily drop and reacquire elevated privileges. This mechanism is why setuid root binaries are high-value targets: any vulnerability in backup_tool could yield root-level access to an unprivileged attacker.

Exam trap

The trap here is believing that setuid changes the real UID as well, when in fact it only changes the effective UID and saved set-user-ID, leaving the real UID intact for accountability.

206
MCQeasy

A junior administrator is preparing a new Ubuntu server for production. The security policy states that the root account must not be usable for direct interactive logon, and that administrative tasks must be performed through a named account with elevated privileges. Which configuration change best enforces this policy?

A.Lock the root account password with 'passwd -l root' and grant administrative rights to named accounts via sudo.
B.Change root's shell to /sbin/nologin in /etc/passwd and delete the root entry from /etc/shadow.
C.Set a very long, complex password for root and store it in a sealed envelope in a safe.
D.Add 'PermitRootLogin no' to /etc/ssh/sshd_config and restart the SSH service, leaving local console root logon enabled.
AnswerA

Locking the root password with passwd -l root prepends an exclamation mark to the hash in /etc/shadow, disabling password-based logon for root while still allowing services and sudo to function. Granting named accounts sudo privileges ensures accountability and satisfies the policy that administrative tasks be performed through individual accounts with elevation.

Why this answer

The policy demands that root cannot be used for interactive logon and that administrative work be done through named accounts with elevated privileges. Locking the root password prevents password-based interactive authentication while sudo allows auditable, per-user elevation. Disabling only SSH root logon leaves console access open, and deleting root from /etc/shadow risks breaking the system.

A long password still permits direct root logon and is not a technical enforcement of the policy.

Exam trap

The trap here is equating 'PermitRootLogin no' with a complete ban on root logon, when it only affects the SSH service.

207
MCQmedium

A financial services firm separates its cardholder data environment from the corporate network using internal VLANs and a next-generation firewall. The security architect wants to add a detective control that will identify malicious traffic that successfully crosses between segments. Which solution best fits this requirement?

A.Configure private VLANs to prevent hosts within the cardholder data environment from communicating with each other.
B.Deploy a web application firewall (WAF) in front of the cardholder data environment.
C.Enable 802.1X port-based network access control on all switch ports in both VLANs.
D.Install a network intrusion detection system (NIDS) with a span port monitoring traffic between the VLANs.
AnswerD

A NIDS receiving a copy of inter-segment traffic via a SPAN port analyzes packets for known attack signatures and anomalies. If malicious traffic crosses the segmentation boundary, the NIDS raises an alert, providing the detective layer the architect wants. It does not block traffic, which matches the requirement for detection rather than prevention.

Why this answer

The architect needs visibility into traffic that crosses the segmentation boundary, which is a detective control function. A network intrusion detection system monitoring a SPAN port sees copies of packets traversing the inter-VLAN link and can alert on malicious patterns. WAFs, 802.1X, and private VLANs either focus on web traffic or enforce preventive access restrictions, none of which detect successful cross-segment intrusions.

Exam trap

The trap here is confusing segmentation enforcement controls with monitoring controls, when the scenario explicitly asks for detection after traffic already crosses a boundary.

208
MCQmedium

You are auditing a Windows server and need to identify which user accounts have recently utilized elevated privileges. Which specific Event ID should you prioritize in the Security log?

A.Event ID 4624
B.Event ID 4672
C.Event ID 4720
D.Event ID 1102
AnswerB

This event explicitly indicates that a logon session has been assigned special privileges. It is the definitive audit log entry for identifying administrative access at the moment of login, providing a clear trail for security analysts monitoring for unauthorized privilege usage.

Why this answer

Event ID 4672 is generated immediately upon a successful logon when a user is assigned special privileges, such as SeDebugPrivilege or SeBackupPrivilege. Auditing this ID allows administrators to track the lifecycle of administrative access, effectively mapping privilege escalation to specific user sessions. Monitoring this is critical for detecting potential account compromise or unauthorized administrative activity within the Windows environment.

Exam trap

Test-takers often look for standard successful logon IDs like 4624 instead of checking for special privilege assignment events during administrative sessions.

209
MCQmedium

A financial services firm is aligning its security program with the CIS Critical Security Controls. The CISO wants to ensure that the organization can measure the effectiveness of its security posture over time and prioritize improvements. Which of the following should the security team implement to achieve this?

A.Adopt the CIS Risk Assessment Method (CIS RAM) to identify, analyze, and prioritize risks based on the CIS Controls.
B.Conduct a penetration test to identify vulnerabilities in the organization's external-facing infrastructure.
C.Deploy a SIEM solution to collect and correlate security events from all network devices.
D.Implement the NIST Cybersecurity Framework to map current activities to the five core functions.
AnswerA

CIS RAM is a prescriptive risk assessment method designed to help organizations implement the CIS Controls by identifying and prioritizing risks. It provides a structured approach to measure security posture and make informed decisions about resource allocation, directly supporting the CISO's goal of tracking effectiveness and prioritizing improvements.

Why this answer

CIS RAM is specifically designed to help organizations implement the CIS Controls by providing a repeatable, risk-based assessment method. It enables the security team to measure the effectiveness of controls, identify gaps, and prioritize remediation efforts. Other options, while valuable, do not offer the same direct alignment with CIS Controls for measuring and improving security posture over time.

Exam trap

The trap here is assuming that any recognized framework or tool (like NIST CSF or a SIEM) can fulfill the need for a CIS Controls-specific measurement and prioritization method, when only CIS RAM is purpose-built for that.

210
MCQhard

An architect is designing a defensible architecture that must detect reconnaissance scanning against a sensitive research subnet without alerting on normal vulnerability-scanner traffic that the security team runs weekly from an authorized scanner host. The design will use an intrusion detection sensor on a SPAN port. Which combination of capabilities best meets the requirement?

A.Deploy an anomaly-based IDS with a baseline that includes the weekly scanner, and alert only when traffic deviates from that baseline.
B.Deploy a signature-based IDS and disable all scan-detection signatures, relying on firewall logs to reveal reconnaissance activity.
C.Deploy a signature-based IDS tuned to scan signatures and configure a pass rule for the authorized scanner's IP address above the scan-detection rules.
D.Deploy a signature-based IDS and configure a suppression threshold that ignores any source generating more than one hundred alerts per hour.
AnswerC

A pass rule placed before the detection signatures tells the sensor to ignore traffic from the trusted scanner, while scan-detection signatures still fire for any other source probing the research subnet. This preserves visibility of real reconnaissance and suppresses the known benign weekly scan, which is precisely the tuning the requirement demands on a SPAN-based sensor.

Why this answer

Suppression must be tied to the identity of the authorized scanner, and a pass rule ordered ahead of the scan-detection signatures achieves that on a signature-based sensor. Other sources probing the research subnet still generate alerts, so reconnaissance remains detectable. Anomaly baselining, disabled signatures, and volume thresholds all fail because they suppress or remove detection without distinguishing the trusted scanner from an attacker.

Exam trap

The trap here is treating volume-based threshold suppression as equivalent to an identity-based pass rule, when only the latter exempts a specific trusted host.

211
Multi-Selecthard

Which TWO of the following statements are true regarding the use of WPA3 compared to WPA2?

Select 2 answers
A.WPA3 uses SAE to replace the vulnerable WPA2 PSK exchange.
B.WPA3 is fully backward compatible with all WEP-based devices.
C.WPA3 mandates the use of Protected Management Frames (PMF).
D.WPA3 removes the requirement for 802.1X authentication entirely.
E.WPA3 encryption is strictly limited to 64-bit keys.
AnswersA, C

SAE (Simultaneous Authentication of Equals) provides stronger protection than the PSK mechanism used in WPA2. It defends against offline dictionary attacks because the key exchange does not rely on a simple hash of the password, preventing attackers from capturing the handshake to crack it later.

Why this answer

WPA3 introduces significant security improvements over WPA2. SAE (Simultaneous Authentication of Equals) replaces the vulnerable PSK exchange, providing forward secrecy and protection against offline dictionary attacks. Additionally, WPA3 mandates Protected Management Frames (PMF), which prevents the de-authentication attacks that plague WPA2.

These enhancements make WPA3 the current standard for protecting wireless networks against common interception and session-hijacking techniques.

Exam trap

Candidates often assume WPA3 replaces WPA2-Enterprise or incorrectly believe that WPA3 makes all previous security protocols redundant, missing that WPA3 specifically addresses PSK weaknesses and management frame vulnerabilities.

212
MCQmedium

A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?

A.User Account Control (UAC)
B.BitLocker Drive Encryption
C.Share Permissions
D.Group Policy Object (GPO) Inheritance
AnswerC

Share permissions act as the first gatekeeper for network resources. If the Share permission is set to 'Deny' or does not include the user, they cannot access the contents regardless of their NTFS permissions. Both layers must permit access for the user to view or modify files.

Why this answer

Effective access in Windows is the intersection of NTFS permissions and Share permissions. If an account is denied access at the Share level, it will override any Read permissions granted via NTFS. Understanding this dual-layer architecture is critical for troubleshooting access issues, as security professionals must verify both file system attributes and network-level sharing configurations to ensure that policies are applied correctly and consistently across the environment.

Exam trap

Candidates often focus solely on NTFS permissions and assume that if they are correct, access is granted. They forget that Share permissions are a separate layer that can block access entirely.

213
MCQhard

A media company uses a public cloud IaaS environment to render video. An attacker compromises an application running on an EC2 instance and attempts to retrieve temporary credentials from the instance metadata service to access an S3 bucket containing unreleased content. The security team wants to prevent this credential theft without breaking legitimate application access. Which measure most effectively mitigates this risk?

A.Disable the S3 bucket's default encryption so that stolen credentials cannot decrypt the content.
B.Attach a broader IAM role to the instance so that stolen credentials have more permissions but are easier to rotate.
C.Store long-term IAM user access keys in the application configuration file on the instance.
D.Enforce IMDSv2 with a hop limit of 1 and require token-based sessions for metadata requests.
AnswerD

IMDSv2 requires a PUT request to obtain a session token before metadata can be read, which blocks simple server-side request forgery and many credential-theft techniques. Setting the hop limit to 1 prevents containers and proxies from reaching the metadata endpoint. Together these controls protect the instance role credentials while legitimate application code can still retrieve them using the token flow.

Why this answer

Instance metadata service credentials are a frequent target because they grant the instance's role permissions. IMDSv2 adds a session-oriented token requirement that defeats simple SSRF and credential-harvesting scripts, while a hop limit of 1 blocks access from containers or proxies on the instance. These controls preserve legitimate access through the token flow while removing the easiest paths to steal temporary credentials.

Exam trap

The trap here is thinking that broadening permissions or rotating keys solves credential theft, when the real fix is hardening the metadata service so credentials cannot be retrieved in the first place.

214
Multi-Selecthard

A security team is hardening a fleet of Windows 10 workstations against exploit techniques used by malicious code. The team wants to enable operating system features that make it harder for an attacker to execute arbitrary code in memory and to bypass address space randomization. Which two features should the team enable? (Choose two.)

Select 2 answers
A.Address Space Layout Randomization (ASLR) with system-wide mandatory enforcement.
B.Control Flow Guard (CFG) configured only for applications that opt in.
C.Structured Exception Handling Overwrite Protection (SEHOP) in audit-only mode.
D.Data Execution Prevention (DEP) in opt-out mode.
E.Windows Defender Application Control (WDAC) in audit mode.
AnswersA, D

ASLR randomizes the base addresses of executable images, DLLs, the stack, and the heap, which makes it difficult for an attacker to reliably predict where code or gadgets reside. Enforcing ASLR system-wide through Windows Defender Exploit Guard's mandatory ASLR setting ensures that even applications not compiled with ASLR support are randomized, increasing the difficulty of exploitation. This is the second correct hardening feature for the scenario.

Why this answer

Data Execution Prevention and system-wide mandatory Address Space Layout Randomization are the two operating system features that directly raise the bar for memory-corruption exploits. DEP prevents execution of code from data pages, defeating simple shellcode placement, while mandatory ASLR randomizes memory layout so attackers cannot rely on fixed addresses. Together they force attackers to find information leaks or other bypasses, which is the intended hardening posture for the workstation fleet.

Exam trap

The trap here is selecting real mitigations that are configured in audit or opt-in mode, which log or partially apply the protection instead of fully enforcing it.

215
MCQhard

A security administrator is configuring a macOS Big Sur endpoint to meet a compliance requirement that mandates all system extensions must be explicitly approved by the user. Which command should the administrator use to verify that only approved system extensions are loaded?

A.systemextensionsctl list
B.csrutil status
C.spctl --status
D.kextstat
AnswerA

The systemextensionsctl list command displays all installed system extensions and indicates whether each is approved by the user or pending approval. This directly addresses the compliance requirement to verify that only approved system extensions are loaded. It provides the necessary status information to confirm user approval.

Why this answer

System extensions are a modern replacement for kernel extensions and require user approval before they can load. The systemextensionsctl list command provides a detailed list of all system extensions along with their approval status. This allows administrators to verify that only approved extensions are present, meeting the compliance requirement.

The other commands either list kernel extensions or check different security features, so they do not provide the needed information.

Exam trap

The trap here is conflating system extensions with kernel extensions; systemextensionsctl list is the correct tool for system extensions, while kextstat is for kernel extensions.

216
MCQmedium

An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?

A.tail -f /var/log/auth.log
B.head -n 20 /var/log/auth.log
C.less +F /var/log/auth.log
D.cat /var/log/auth.log | grep -v 'accepted'
E.more /var/log/auth.log
AnswerA, C

The '-f' flag tells the tail utility to follow the file, meaning it will continuously display new lines as they are appended to the log. This is the industry-standard method for live log monitoring and immediate detection of authentication failures, such as repeated SSH login attempts or brute-force attacks.

Why this answer

Monitoring logs in real-time is a fundamental skill for GSEC professionals to detect ongoing attacks or system errors. The 'tail -f' command is the standard utility for following a file's growth. Alternatively, 'less +F' offers a more robust interface that allows the admin to toggle between real-time monitoring and static analysis, providing better flexibility when investigating complex log entries during an active incident response scenario.

Exam trap

Candidates often choose static commands like 'cat' or 'more', which do not update in real-time, failing to realize that active incident response requires continuous monitoring of log file growth.

217
Multi-Selecthard

A financial services firm is selecting a web application firewall (WAF) to protect an internet-facing banking portal that uses TLS 1.3 exclusively. The security architect must ensure the WAF can inspect encrypted sessions and detect attacks that unfold across many requests from the same client. Which TWO capabilities are MOST relevant to these requirements? (Choose two.)

Select 2 answers
A.Configuring the WAF to operate only in detection mode with alerts sent to a SIEM.
B.Enabling promiscuous mode on the WAF's management interface.
C.Disabling HTTP keep-alive so every request opens a fresh TCP connection.
D.Terminating TLS at the WAF using a certificate and private key trusted by the portal's clients.
E.Maintaining per-client session state and scoring correlated requests over time.
AnswersD, E

To inspect TLS 1.3 payloads, the WAF must be a TLS endpoint, which means presenting a certificate and possessing the corresponding private key so it can decrypt, examine, and re-encrypt sessions. Without this termination capability the WAF only sees ciphertext and cannot evaluate HTTP request content, making it useless against application-layer attacks on the portal.

Why this answer

Inspecting TLS 1.3 forces the WAF to act as a TLS endpoint with the portal's certificate and key, because encrypted payloads are otherwise opaque. Detecting attacks spread across many requests requires persistent per-client session tracking and behavioral scoring, so those two capabilities together satisfy the architect's requirements.

Exam trap

The trap here is equating passive packet capture features, such as promiscuous mode, with the active decryption and session correlation a WAF needs to inspect modern TLS.

218
MCQhard

An organization is reviewing CIS Control 11: Data Recovery. Which of the following activities best demonstrates adherence to the 'testing' requirement of this control?

A.Running a full system backup every night at 2:00 AM.
B.Storing all backup tapes in an off-site, climate-controlled facility.
C.Conducting a periodic, documented restore process to verify data integrity.
D.Encrypting all backup media to prevent unauthorized access.
AnswerC

Performing a documented, periodic restore test is the core requirement for Control 11. It proves that the backup system is working as intended, data is not corrupted, and the team knows the necessary steps to recover critical business systems within the required recovery time objectives after an incident.

Why this answer

The testing requirement in CIS Control 11 is critical because backups are useless if they cannot be successfully restored. Organizations must not only perform regular backups but also systematically test those backups to verify data integrity and recovery speed. This ensures that in the event of a ransomware attack or accidental data loss, the organization has a reliable, validated path to restore operations quickly and minimize downtime effectively.

Exam trap

Candidates often equate 'testing' with simply verifying that a backup job completed successfully. They miss that the actual requirement is to perform a restoration to verify data integrity.

219
MCQhard

A security analyst is investigating a suspected man-in-the-middle attack against an HTTPS service. The analyst finds that the client is ignoring certificate validation errors. Which cryptographic failure is most likely occurring?

A.Lack of Perfect Forward Secrecy
B.Improper certificate chain verification
C.Weak cipher suite negotiation
D.Use of outdated TLS 1.0 protocol
AnswerB

If the client code ignores certificate validation, it fails to verify the digital signature of the certificate against trusted Root CAs. This allows any attacker to issue a fraudulent certificate for the target domain, which the client will accept as valid, thereby facilitating a successful man-in-the-middle attack scenario.

Why this answer

The failure to validate certificates allows an attacker to present a forged certificate that the client blindly trusts. This breaks the fundamental trust model of PKI, allowing an attacker to intercept, inspect, and potentially modify encrypted traffic. This is a common flaw in poorly configured internal applications where developers disable validation to bypass expired or self-signed certificate warnings, creating a significant security hole that leaves users vulnerable to eavesdropping and credential theft.

Exam trap

Candidates often select general man-in-the-middle or encryption algorithm failures, missing that the root cause specifically stems from improper validation of the certificate chain by the client application.

220
MCQmedium

A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?

A.Configure AppLocker default rules to allow only administrators to run PowerShell scripts in the environment.
B.Disable the Windows Script Host on all workstations by setting the Enabled registry value under WSH settings to 0.
C.Add the finance department's subnet to the Microsoft Defender Antivirus network inspection exclusion list.
D.Enable PowerShell script block logging and module logging through Group Policy, then collect the events in Windows Event Forwarding for analysis.
AnswerD

Script block logging records the de-obfuscated script content that PowerShell actually executes, even when the command line is Base64-encoded, and module logging captures pipeline execution details. Forwarding those events to a central collector preserves the decoded payload for investigation while giving defenders visibility into the malicious behavior, directly mitigating this encoded PowerShell execution scenario.

Why this answer

Encoded PowerShell commands hide the real script from casual command-line inspection, so the effective mitigation is to force PowerShell to log the de-obfuscated script blocks and module activity. Centralizing those events through Windows Event Forwarding lets analysts review the decoded payload and build detections, addressing both mitigation and evidence preservation without breaking legitimate administration.

Exam trap

The trap here is assuming that disabling a scripting host or restricting script files stops all PowerShell abuse, when encoded commands can execute without any script file on disk.

221
Multi-Selectmedium

A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)

Select 2 answers
A.kmutil showloaded
B.spctl --assess --verbose
C.kextstat
D.systemextensionsctl list
E.csrutil status
AnswersA, C

The kmutil showloaded command displays information about currently loaded kernel extensions and other kernel collections. It is a modern replacement for kextstat and provides detailed output that can help identify unauthorized or malicious kexts. It is an appropriate tool for investigating kernel-level compromise on macOS.

Why this answer

To check for malicious kernel extensions, an analyst should use tools that list loaded kexts. The kextstat command provides a list of loaded kernel extensions, while kmutil showloaded offers similar information with more detail. Both are appropriate for identifying unauthorized kexts.

The other commands focus on system extensions, SIP status, or Gatekeeper assessments, which do not directly reveal loaded kernel extensions.

Exam trap

The trap here is confusing system extensions with kernel extensions; systemextensionsctl list does not show kernel extensions, and csrutil or spctl do not list loaded kexts.

222
MCQmedium

You are a security consultant reviewing a Windows Server 2016 environment. The client wants to ensure that all administrative actions are logged and can be traced back to individual administrators. Currently, all administrators use a shared domain admin account. Which security control should you recommend to meet this requirement?

A.Configure a Group Policy Object to enable 'Audit process tracking' for all servers.
B.Enable the 'Audit: Force audit policy subcategory settings' policy.
C.Implement separate administrative accounts for each administrator.
D.Enable 'Audit: Shut down system immediately if unable to log security audits'.
AnswerC

Using separate accounts ensures that each administrator's actions are logged under their unique account. This allows auditing and traceability. Shared accounts prevent attribution. By implementing individual accounts, you can track who performed which action. This is a fundamental principle of accountability and directly solves the scenario's requirement.

Why this answer

The core issue is that shared accounts prevent attribution. To trace administrative actions to individuals, each administrator must have a unique account. This ensures that audit logs record the specific user who performed each action.

Other options address audit policy settings but do not solve the fundamental problem of shared credentials.

Exam trap

The trap here is focusing on audit policy configuration when the real problem is the use of a shared account, which makes individual attribution impossible regardless of audit settings.

223
MCQmedium

A security analyst is reviewing file server permissions and notices that a user, Elena, has the 'Modify' permission on a folder via group membership in 'Project_X', but she is also a member of the 'Contractors' group, which has an explicit 'Deny' for 'Write'. Elena reports she cannot edit any files in the folder. What is the most likely explanation for this behavior?

A.The 'Deny' permission only applies if Elena is directly listed, not via group membership.
B.The 'Write' permission is not included in the 'Modify' permission, so the Deny for Write does not affect Modify.
C.The 'Deny' permission for the 'Contractors' group takes precedence over the 'Allow' permission inherited from 'Project_X'.
D.The 'Modify' permission from 'Project_X' is inherited and therefore is overridden by the explicit 'Deny'.
AnswerC

In Windows access control, explicit Deny entries in an ACL override any Allow permissions, whether inherited or explicit. Because Elena is a member of 'Contractors', the Deny for Write applies directly to her, blocking the Modify permission from 'Project_X'. This is by design to ensure security restrictions are enforced.

Why this answer

Windows access control evaluates Deny entries before Allow entries. An explicit Deny for a group applies to all its members, and it overrides any Allow permissions, even those granted through other group memberships or inheritance. Thus, Elena's Write access is blocked by the Deny on the Contractors group, despite her Modify permission from Project_X.

Exam trap

The trap here is assuming that the most permissive permission wins or that group membership does not trigger Deny entries.

224
MCQhard

A healthcare organization is implementing CIS Control 14: Security Awareness and Skills Training. The security manager needs to ensure that the training program effectively reduces phishing susceptibility among employees. Which of the following approaches best aligns with the control's requirements?

A.Implement a phishing simulation program with regular campaigns, provide immediate feedback to users who click, and track improvement over time.
B.Require employees to complete a computer-based training module on phishing once per quarter and pass a quiz.
C.Send monthly security newsletters to all staff highlighting recent phishing trends and best practices.
D.Conduct annual security awareness training for all employees and track completion rates.
AnswerA

This approach aligns with CIS Control 14 by providing continuous, practical training through simulated phishing attacks. Immediate feedback educates users in the moment, and tracking improvement measures the program's effectiveness. It goes beyond mere completion tracking to actively reduce susceptibility by reinforcing secure behavior and adapting training based on results.

Why this answer

CIS Control 14 emphasizes continuous security awareness training that includes simulated phishing exercises to test and reinforce employee skills. A program with regular phishing simulations, immediate feedback, and tracking of improvement directly measures and reduces susceptibility. Other options are either too infrequent or passive, failing to provide the practical, ongoing reinforcement that the control requires.

Exam trap

The trap here is equating security awareness with periodic training or communications, when CIS Control 14 specifically calls for simulated phishing and continuous reinforcement to effectively change behavior.

225
Multi-Selecthard

During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?

Select 3 answers
A.Resetting compromised user passwords
B.Analyzing the memory dump for malware signatures
C.Patching the vulnerability used for initial access
D.Re-imaging infected systems from a known-good source
E.Drafting an incident report for executive leadership
AnswersA, C, D

If an attacker has stolen credentials, simply removing the backdoor is insufficient because the attacker can still authenticate using the compromised account. Resetting passwords is a mandatory eradication step to prevent the adversary from regaining access via legitimate authentication channels after the malicious artifacts are removed.

Why this answer

Eradication aims to completely remove the adversary's presence. Simply deleting a file is rarely sufficient; attackers often leave multiple persistence mechanisms or backdoors. By resetting credentials, patching the underlying vulnerability, and re-imaging systems, the organization ensures that the attacker cannot easily return, effectively closing the window of opportunity that allowed the initial unauthorized access to occur and persist.

Exam trap

Candidates often choose only one action (like patching) while ignoring that eradication must address the attacker's persistence mechanisms, such as compromised credentials and backdoors, to be truly effective.

Page 2

Page 3 of 5

Page 4

All pages