Courseiva

GIAC Security Essentials (GSEC) — Questions 301–351

351 questions total · 5pages · All types, answers revealed

Page 4

Page 5 of 5

301
Multi-Selectmedium

Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?

Select 2 answers
A.To eliminate the need for regular security patching.
B.To increase the difficulty and cost for an attacker to succeed.
C.To ensure that a single control failure does not result in a breach.
D.To replace the requirement for user security awareness training.
E.To centralize all logs into a single storage location.
AnswersB, C

By implementing multiple, heterogeneous layers of security, an organization forces an attacker to expend more time and resources. Each additional layer increases the complexity of the attack chain, raising the likelihood of detection and providing more opportunities for the security team to identify and stop the adversary.

Why this answer

Defense in depth aims to delay attackers, increase the probability of detection, and ensure that a single point of failure does not lead to a total security compromise. These objectives are achieved by creating layers that require an attacker to defeat multiple, distinct security measures. This approach is essential for modern enterprises where perimeter defenses can be bypassed via phishing or zero-day vulnerabilities, making internal detection and mitigation capabilities absolutely vital.

Exam trap

Candidates often select incorrect options that imply defense in depth can completely prevent all initial attacks or eliminate risk entirely, rather than merely increasing cost and resilience.

302
MCQhard

A security engineer is reviewing a production RHEL 9 server and finds that several users have entries in /etc/sudoers granting them NOPASSWD for specific commands. The engineer wants to verify which users can run commands as root without a password and also check for any syntax errors in the sudoers configuration. Which approach provides the most reliable verification?

A.Run 'sudo -v' to validate the sudoers file and then use 'getent group sudo' to list all privileged users.
B.Run 'sudo -l' as each user to list their allowed commands and visually inspect /etc/sudoers for NOPASSWD entries.
C.Check the file permissions on /etc/sudoers and /etc/sudoers.d, then review the sudo log in /var/log/secure for NOPASSWD usage.
D.Use 'visudo -c' to check syntax and 'grep -r NOPASSWD /etc/sudoers /etc/sudoers.d/' to enumerate passwordless entries.
AnswerD

visudo -c parses the sudoers file and any included files, reporting syntax errors without modifying anything, while a recursive grep across /etc/sudoers and /etc/sudoers.d identifies all NOPASSWD grants. Together they provide reliable syntax validation and a complete inventory of passwordless command authorizations, which is exactly what the engineer needs for verification.

Why this answer

To reliably verify passwordless sudo grants, the engineer needs to enumerate all NOPASSWD entries across the main sudoers file and any drop-in files, and to validate syntax. visudo -c performs a syntax check on all included files, while a recursive grep captures every NOPASSWD occurrence. Approaches that rely on individual user sessions or logs are either incomplete or reactive, and checking group membership alone misses per-user and per-command grants.

Exam trap

The trap here is assuming that sudo -l or group membership reveals all passwordless grants, when included files under /etc/sudoers.d can contain additional entries.

303
MCQhard

A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?

A.Argon2
B.PBKDF2
C.bcrypt
D.SHA-256 with a random salt
AnswerA

Argon2 is the winner of the Password Hashing Competition and is designed to resist GPU cracking. It allows tuning of time cost (CPU), memory cost, and parallelism. This makes it highly adaptable to different hardware and security requirements. The scenario explicitly requires tuning of CPU and memory costs and resistance to GPU attacks, which Argon2 delivers. It is the recommended choice for new applications.

Why this answer

Argon2 is specifically designed to be memory-hard and CPU-hard, with tunable parameters for time, memory, and parallelism. This makes it resistant to GPU-accelerated cracking and allows customization for different environments. bcrypt and PBKDF2 lack memory tuning, and SHA-256 is too fast. Therefore, Argon2 is the correct choice for the password hashing scheme.

Exam trap

The trap here is assuming that any slow hashing algorithm like bcrypt or PBKDF2 is sufficient, overlooking the specific requirement for tunable memory costs that only Argon2 provides.

304
MCQeasy

Which of the following is the most effective way to prevent secrets (such as API keys) from being leaked via container images?

A.Encrypt the Dockerfile using a secret key before building.
B.Use orchestrator-native secret management to inject secrets at runtime.
C.Delete the secrets in a subsequent RUN layer during the build.
D.Set the file permissions on the secret to 600 after copying it.
AnswerB

Runtime injection ensures that secrets reside only in the memory of the container and are not persisted in the image layers. This prevents secrets from being exposed through registry access or image analysis, allowing for easier rotation and centralized auditing of secret usage within the containerized application environment.

Why this answer

Secrets should never be baked into container images because they remain in the image layers even if deleted in later steps. Once an image is pushed to a registry, those secrets are accessible to anyone with pull access. Using orchestrator-native secret management (like Kubernetes Secrets or Vault) ensures that sensitive data is injected at runtime, keeping it out of the persistent image layers and the source control history.

Exam trap

Candidates frequently select multi-stage builds or container image scanning, forgetting that while these reduce image size or find bugs, they do not prevent secrets from persisting in image layers.

305
MCQhard

A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?

A.The token is unsigned, allowing an attacker to modify the payload and forge valid tokens.
B.The token uses a weak signing algorithm that can be brute-forced to recover the secret key.
C.The token is vulnerable to replay attacks because it lacks an expiration claim.
D.The token is encrypted, so the contents cannot be read by an attacker.
AnswerA

When the JWT header specifies "alg": "none", it means the token has no signature. An attacker can alter the payload (e.g., change user privileges) and since there is no signature to verify, the server may accept the modified token if it does not properly reject "none" algorithms. This is a critical vulnerability that can lead to authentication bypass and privilege escalation.

Why this answer

A JWT with "alg": "none" is unsigned, meaning it has no integrity protection. An attacker can tamper with the payload and, if the server accepts such tokens, forge arbitrary claims. This can lead to authentication bypass or privilege escalation.

The correct answer identifies that the token is unsigned and can be modified. The other options mischaracterize the token as encrypted, weakly signed, or solely vulnerable to replay, missing the core issue of missing signature verification.

Exam trap

The trap here is assuming that "none" is a valid secure algorithm or that it provides some form of protection, when in reality it means the token is completely unsigned.

306
MCQmedium

A security administrator is configuring a macOS fleet to enforce that only apps signed with an Apple-issued Developer ID certificate and notarized by Apple can run. The administrator wants to verify the current Gatekeeper assessment status of a downloaded app at /Users/analyst/Downloads/Tool.app. Which command should the administrator use to perform this check?

A.xattr -l /Users/analyst/Downloads/Tool.app
B.codesign --verify --deep --strict /Users/analyst/Downloads/Tool.app
C.system_profiler SPApplicationsDataType
D.spctl --assess --type execute --verbose /Users/analyst/Downloads/Tool.app
AnswerD

The spctl command is the system policy control tool that evaluates Gatekeeper assessments. Using --assess with --type execute and --verbose against the app path returns whether the app is accepted by Gatekeeper and the reason for rejection, directly confirming notarization and Developer ID signing status for the specified app.

Why this answer

Gatekeeper assessment is performed by the spctl utility, which consults system policy to decide whether an app is permitted to execute. Running spctl with the assess action, the execute type, and verbose output against the target app returns an acceptance or rejection verdict along with the reason, which directly reflects Developer ID signing and notarization requirements enforced on the endpoint.

Exam trap

The trap here is assuming that verifying the code signature with codesign proves Gatekeeper will allow the app, when signature integrity and Gatekeeper policy are separate checks.

307
MCQhard

A security engineer is designing a secure enterprise environment and needs to deploy network intrusion detection sensors to monitor east-west traffic moving between virtual machines inside an internal virtualization cluster. Which deployment method ensures the sensors successfully inspect internal segment traffic without introducing a single point of failure for packet forwarding?

A.Placing a dedicated physical inline bump-in-the-wire network intrusion prevention system between every internal virtual switch uplink.
B.Configuring hypervisor-level distributed virtual switches to mirror east-west traffic to dedicated virtual security monitoring appliances.
C.Routing all inter-VLAN traffic through a single legacy perimeter firewall using hardware router-on-a-stick configurations.
D.Disabling all stateful packet inspection on internal firewalls to allow maximum throughput for east-west virtualization traffic.
AnswerB

Hypervisor-level distributed switching capabilities can securely replicate internal virtual machine traffic patterns and send packet copies to virtualized sensor nodes. This out-of-band monitoring approach guarantees comprehensive visibility into east-west communications without risking packet drop or network downtime.

Why this answer

Using virtual tap interfaces or distributed software switches configured for port mirroring allows security sensors to receive copies of internal traffic traversing the hypervisor backplane. This approach ensures comprehensive visibility into east-west lateral movement without altering inline packet forwarding paths, maintaining network availability while delivering the necessary telemetry for threat detection engines.

Exam trap

Candidates often choose inline network security appliances that introduce a single point of failure or latency, forgetting that the question specifically requests monitoring internal east-west traffic without disrupting packet forwarding.

308
MCQmedium

An enterprise development team is designing a Kubernetes cluster deployment where application containers frequently interact with cloud provider APIs. To minimize security blast radius, which architectural practice provides the most effective credential isolation per pod?

A.Store cloud provider credentials in base64-encoded Kubernetes Secret objects and mount them as environment variables.
B.Configure cluster-wide IAM roles on the underlying worker nodes and allow all hosted pods to inherit administrative permissions.
C.Implement service account token volume projection with short-lived auditable tokens scoped to individual application requirements.
D.Embed the static cloud API keys directly into the container base image layers to ensure consistency across deployments.
AnswerC

Projected service account tokens provide automatically rotated, cryptographically signed tokens with strict audience limitations. This ensures that even if a token is exfiltrated, its lifespan is extremely short and its usability is strictly bounded to intended APIs.

Why this answer

Service account token volume projection utilizes short-lived tokens cryptographically signed by the cluster, mounting them securely into specific pods with restricted audiences. This approach replaces static long-lived credentials stored in environment variables or generic secrets, significantly reducing lateral movement risks if an application is compromised.

Exam trap

Candidates often suggest static secrets or Kubernetes Secrets objects, failing to realize that these are long-lived and pose a higher risk compared to short-lived, projected tokens.

309
MCQmedium

A university is implementing CIS Control 6: Access Control Management. They want to ensure that user accounts are properly managed. Which of the following actions best aligns with the requirement to manage the lifecycle of user accounts?

A.Conducting quarterly reviews of all user accounts to identify and disable inactive accounts.
B.Implementing multi-factor authentication for all administrative access to servers.
C.Deploying a privileged access management (PAM) solution to vault administrative credentials.
D.Enforcing a password complexity policy that requires 12 characters with mixed case and symbols.
AnswerA

CIS Control 6 requires managing the lifecycle of user accounts, including periodic reviews to disable inactive accounts. Quarterly reviews help ensure that accounts are removed when no longer needed, reducing the attack surface. This action directly supports the control's intent.

Why this answer

Quarterly reviews of user accounts directly support the lifecycle management requirement of CIS Control 6. By identifying and disabling inactive accounts, the university reduces the risk of unauthorized access through stale credentials. Other actions like password policies, MFA, and PAM are valuable but do not fulfill the specific need to manage account lifecycles across all users.

Exam trap

The trap here is focusing on authentication mechanisms like MFA or password policies, which are important but not the same as account lifecycle management.

310
MCQhard

An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?

A.Members of Temp_Contractors will be denied access to the entire C: drive because Deny permissions propagate upward.
B.The Deny permission will be ignored because inherited Allow permissions take precedence over explicit Deny permissions.
C.Members of Temp_Contractors will be denied access to C:\Audit, but will retain their inherited permissions on other folders.
D.Members of Temp_Contractors will still have access to C:\Audit because they are also members of the Users group, which has inherited Allow permissions.
AnswerC

An explicit Deny permission on C:\Audit overrides any inherited Allow permissions for that folder and its subfolders. Since the Deny is applied only to C:\Audit, it does not affect other folders on the C: drive. Thus, Temp_Contractors are denied access to C:\Audit but retain access elsewhere as per inherited permissions.

Why this answer

Explicit Deny permissions override inherited Allow permissions. Placing a Deny Full Control for Temp_Contractors on C:\Audit blocks their access to that folder and its subfolders (if inheritance is enabled), but does not affect other folders on the C: drive. Therefore, the correct outcome is that Temp_Contractors are denied access to C:\Audit while retaining access to other folders.

Exam trap

The trap here is thinking that Deny permissions propagate upward or that inherited Allow can override an explicit Deny. In reality, explicit Deny takes precedence and applies only to the object and its children.

311
MCQeasy

A security administrator is reviewing the security configuration of a Windows 10 workstation. The administrator notices that the workstation has the 'Secondary Logon' service disabled. Which of the following is the MOST likely impact of this configuration?

A.Users will be unable to log on interactively to the workstation.
B.Remote Desktop connections to the workstation will be blocked.
C.Users will be unable to run applications as a different user using the 'Run as different user' option.
D.The workstation will be unable to join a domain.
AnswerC

The Secondary Logon service (seclogon) enables users to start processes under alternate credentials. If this service is disabled, the 'Run as different user' option will fail, and users will not be able to use runas.exe or Shift+right-click to launch applications with different credentials. This is the primary function of the service.

Why this answer

The Secondary Logon service is responsible for allowing users to start processes under alternate credentials. Disabling it prevents the use of 'Run as different user' and runas.exe, but does not affect interactive logon, domain join, or Remote Desktop. Therefore, the most likely impact is the inability to run applications as a different user.

Exam trap

The trap here is assuming that disabling any service will broadly impact system functionality; however, the Secondary Logon service is specifically tied to alternate credential process creation.

312
Multi-Selecthard

Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?

Select 2 answers
A.Get-LocalGroupMember -Group Administrators
B.Get-ScheduledTask
C.Get-Process -IncludeUserName
D.Get-Service | Where-Object {$_.Status -eq 'Running'}
E.Get-WinEvent -LogName Security
AnswersA, B

This cmdlet allows an auditor to list all members of the local Administrators group. Monitoring this group is vital, as attackers often add malicious accounts or elevated service accounts to maintain control over the compromised host during the post-exploitation phase.

Why this answer

Effective auditing requires querying local identity stores and task schedules. 'Get-LocalGroupMember' provides a snapshot of accounts with elevated or specific access, while 'Get-ScheduledTask' identifies persistent malicious mechanisms. Understanding these commands is critical for GSEC professionals to perform rapid host-based forensics, as these two areas are frequent targets for persistence and lateral movement by attackers.

Exam trap

Candidates often select commands related to Active Directory or system-wide auditing rather than host-specific local commands. They fail to distinguish between domain-level management and local server-level forensic auditing.

313
Multi-Selecthard

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

Select 3 answers
A.Grant the build service account passwordless sudo access to all commands to simplify automation.
B.Require all build servers to authenticate users with individual SSH keys and disable password authentication.
C.Disable SELinux on the build server to avoid build failures caused by mandatory access control denials.
D.Store build signing keys on a hardware security module (HSM) that requires dual authorization to use.
E.Run build jobs inside containers that drop all Linux capabilities and use a read-only root filesystem.
AnswersB, D, E

Per-user SSH keys with password authentication disabled prevent credential reuse and brute-force attacks against the build host. Individual keys create accountability and allow revocation without disrupting other engineers. This strengthens identity controls at the host layer, making initial compromise harder and limiting attacker movement.

Why this answer

Reducing the impact of a compromised build server requires layered constraints: container isolation with dropped capabilities and read-only filesystems limits what code can do, HSM-backed signing keys with dual authorization protect the supply chain, and per-user SSH keys harden initial access. Disabling SELinux and granting unrestricted sudo both expand attacker privileges, so they weaken rather than strengthen the layered defense.

Exam trap

The trap here is treating convenience measures such as disabling SELinux or granting broad sudo as acceptable hardening, when they actually remove layers of defense.

314
MCQeasy

Microsoft releases major Windows feature updates under a predictable cadence as part of the Windows as a Service model. How often are Windows 10 and Windows 11 Enterprise feature updates officially released under the modern servicing model?

A.Every month alongside regular cumulative security patches
B.Every six months with equal priority given to spring and autumn releases
C.Once every year, specifically during the second half of the calendar year
D.Once every three years to coincide with major hardware refresh cycles
AnswerC

Microsoft transitioned feature updates for Windows to an annual release cadence occurring in the second half of the calendar year (H2). This predictable annual schedule simplifies IT planning, allowing organizations to establish consistent validation and deployment pipelines.

Why this answer

Feature updates for modern Windows operating systems are released annually in the second half of the calendar year for Enterprise and Education editions. Understanding this release frequency helps security professionals plan robust testing cycles and maintain predictable deployment schedules across corporate networks.

Exam trap

Candidates often rely on older semi-annual release schedules and incorrectly select a twice-yearly frequency instead of recalling the modern annual release cadence for Windows Enterprise.

315
MCQhard

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

A.The RSA key length is insufficient for modern requirements
B.The private key will be stored without passphrase protection
C.The certificate will be self-signed and untrusted
D.The output file format defaults to a deprecated encoding
AnswerB

The -nodes flag explicitly disables encryption of the generated private key. This means the key is saved in cleartext, creating a significant security risk where any user or process with read access to the file can steal the identity of the server without needing to provide a password.

Why this answer

The -nodes flag instructs OpenSSL to generate a private key without a passphrase, leaving it stored in plaintext on the file system. In a production environment, this is critical because an attacker with unauthorized read access to the server's filesystem can immediately compromise the private key. Protecting private keys with a passphrase ensures that even if files are exfiltrated, the keys remain encrypted and unusable without the secret passphrase.

Exam trap

Candidates often mistake the -nodes flag for disabling network connectivity or public key generation, missing its specific role regarding private key passphrase protection.

316
MCQmedium

An incident responder collects volatile data from a compromised Windows 10 workstation before pulling the power. The attacker used a custom executable that is no longer present on disk, but the responder needs to confirm which process spawned it and what child processes it created. Which artifact should the responder examine to establish this parent-child process relationship?

A.The SRUM database's Application Resource Usage table
B.The Sysmon Event ID 1 records in the Microsoft-Windows-Sysmon/Operational log
C.The $MFT entries for the volume where the executable ran
D.The Amcache.hve registry hive's Root\InventoryApplicationFile key
AnswerB

Sysmon Event ID 1 (Process Create) captures the image path, command line, hashes, parent process ID, and parent image for each new process. This directly documents which process spawned the attacker's executable and the children it created, even after the binary is deleted. It is the most reliable volatile artifact for reconstructing the parent-child relationship in this scenario.

Why this answer

Sysmon's Process Create event records the image, command line, hashes, and both parent process ID and parent image for every new process, which is exactly the data needed to reconstruct a process tree after the binary is gone. Other artifacts such as Amcache, $MFT, and SRUM may show that a file existed or ran but do not preserve runtime parent-child relationships.

Exam trap

The trap here is assuming that any artifact showing an executable ran (Amcache, SRUM, Prefetch) also preserves the parent-child process relationships, when only process-creation telemetry such as Sysmon Event ID 1 does.

317
MCQhard

A security architect must ensure that hosts on a guest wireless network cannot reach any internal RFC 1918 subnets, while still allowing guests to reach the internet and a captive portal hosted internally for authentication. The design uses a wireless controller that tunnels guest traffic to a dedicated guest anchor. Which approach best enforces the requirement?

A.Assign guests addresses from an isolated guest subnet and apply an ACL on the guest anchor that denies traffic to all internal RFC 1918 ranges while permitting the captive portal host and internet-bound traffic.
B.Assign guests addresses from an isolated guest subnet and publish a route to the internal network, relying on the internal firewalls' implicit deny to block guest access.
C.Assign guests addresses from an isolated guest subnet and configure the internal core switches to drop all traffic sourced from that subnet.
D.Assign guests addresses from the internal corporate DHCP scope and rely on the wireless controller's client isolation feature to prevent guests from reaching internal hosts.
AnswerA

An isolated guest subnet with an ACL that denies RFC 1918 destinations enforces the no-internal-access requirement at the point where guest traffic is anchored. Explicitly permitting the captive portal host and internet destinations preserves the required services, and the deny rule prevents guests from reaching internal subnets even if they discover their addresses. This is the standard guest-anchor enforcement model.

Why this answer

Guest traffic tunneled to a dedicated anchor can be filtered where it enters the network, and an ACL that denies RFC 1918 destinations while permitting the captive portal and internet traffic enforces exactly the stated policy. Client isolation, core-level blanket drops, and route publication either fail to block internal access or break required services. The anchor is the correct enforcement point because it sees all guest traffic before it reaches internal resources.

Exam trap

The trap here is confusing wireless client isolation, which only separates guests from each other, with filtering that blocks guest access to wired internal subnets.

318
MCQmedium

A security administrator needs to block all incoming traffic to a server except for SSH (port 22) using the nftables framework. Which configuration approach best follows the principle of least privilege?

A.Create a rule to allow port 22 and log all other traffic.
B.Add a rule at the end of the chain that rejects all TCP traffic.
C.Set the default policy of the INPUT chain to ACCEPT.
D.Set the default policy to DROP and add an allow rule for port 22.
AnswerD

This approach implements a 'whitelist' strategy, which is the most secure method for firewall configuration. By dropping all traffic by default, the administrator ensures that only the traffic explicitly defined (in this case, SSH) can reach the server, effectively closing all other ports and reducing the attack surface.

Why this answer

Firewall management is a core skill for securing Linux systems. Moving from iptables to nftables offers more efficient rule processing and a cleaner syntax. Following the principle of least privilege in a firewall context means explicitly denying all traffic by default and only opening the specific ports necessary for business operations.

Exam trap

Candidates often confuse the order of operations, mistakenly adding an allow rule before setting the default policy, or they fail to realize that nftables requires an explicit drop policy to secure the system.

319
MCQhard

A security analyst is reviewing a SIEM alert indicating multiple failed VPN authentication attempts followed by a successful login from an unusual geographic location for the same user account. The analyst wants to determine if this is a compromised account or a legitimate user traveling. Which additional data source would best help the analyst make this determination?

A.Firewall logs showing outbound connections from the VPN-assigned IP address.
B.HR system records of approved travel requests for the user.
C.VPN concentrator logs showing the assigned IP address and session duration for the successful login.
D.Endpoint detection and response (EDR) logs from the user's laptop.
AnswerB

HR travel records can confirm whether the user is authorized to be in that geographic location, directly addressing the question of legitimate travel. If a travel request exists for the same timeframe, it supports the benign explanation. If not, it increases suspicion of compromise. This source provides authoritative business context that is not available in technical logs, making it the best additional data source for this determination.

Why this answer

The key question is whether the login from an unusual location is legitimate travel. HR travel records provide authoritative confirmation of approved travel, directly addressing that question. Technical logs like VPN, EDR, or firewall can show activity but do not confirm the business reason for the location.

HR data is the most direct source to distinguish compromise from legitimate travel.

Exam trap

The trap here is focusing solely on technical logs to determine legitimacy, when business context such as HR travel records is often the most direct evidence for authorized travel.

320
MCQmedium

A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?

A.Deploy the appliance as a routed hop between the two VLANs with a static route on each side.
B.Deploy a TAP aggregator that mirrors both VLANs to the appliance and enable fail-open on the NIC.
C.Deploy a Layer 2 bridge running in inline mode with a hardware bypass fail-to-wire segment.
D.Deploy a SPAN port on the core switch and attach the appliance in passive monitor-only mode.
AnswerC

An inline Layer 2 bridge inspects traffic between the two VLANs while remaining transparent to IP addressing, and a hardware bypass fail-to-wire segment physically shunts packets around the appliance if it loses power, preserving connectivity for clinical systems. This directly satisfies both the inspection and the survivability requirements without renumbering hosts or altering routing.

Why this answer

Transparent inline bridging with a hardware bypass segment keeps the appliance invisible at Layer 3 while still allowing it to enforce policy on traffic crossing between VLANs. The fail-to-wire path guarantees that clinical connectivity survives a power loss, which is the decisive requirement distinguishing this from passive monitoring or routed insertion.

Exam trap

The trap here is assuming that any inline device automatically fails open, when in fact fail-to-wire depends on a dedicated hardware bypass segment rather than software configuration alone.

321
MCQmedium

An enterprise network administrator needs to manage Windows 10 feature updates across a heterogeneous fleet containing both Enterprise and Professional editions. Which deployment methodology natively supports setting a target release version to freeze clients on a specific version like 21H2 while blocking automatic upgrades to later versions?

A.Windows Update for Business configured via Group Policy to specify a target release version
B.Windows Server Update Services automatic approval rules targeting all newly released operating system updates
C.Consumer Windows Update settings modified through local registry edits on each individual workstation
D.Delivery Optimization peer-to-peer distribution bandwidth throttling applied via Local Group Policy
AnswerA

Windows Update for Business enables administrators to define a specific target version, such as Windows 10 version 21H2, directly through Group Policy or MDM solutions. This capability ensures endpoints remain pinned to that exact release until the policy is explicitly changed, preventing unexpected disruptions from subsequent annual feature upgrades.

Why this answer

Setting a target release version through Group Policy or Mobile Device Management allows administrators to freeze workstations on a specific Windows 10 feature update, such as 21H2. This control prevents automatic upgrades to newer major OS versions, ensuring mission-critical line-of-business applications remain compatible without requiring immediate manual intervention across every individual endpoint device.

Exam trap

Candidates frequently confuse Windows Update for Business with WSUS or SCCM. They often select the wrong management tool because they are unaware of the specific 'target release version' policy setting.

322
MCQeasy

A developer is building a container image for a Python web application. During review, a security engineer notices the Dockerfile copies a .env file containing database credentials into the image and deletes it in a later RUN instruction. The engineer explains that this pattern still leaks the credentials. Which of the following best explains why the credentials remain exposed in the final image?

A.The .env file is recreated automatically by the base image's entrypoint at container start.
B.Each Dockerfile instruction creates a layer, and the layer containing the .env file persists in the image history even after a later deletion.
C.Docker automatically backs up deleted files into a hidden volume that is mounted into every container.
D.The .env file is cached in the Docker daemon's build cache and pushed to the registry alongside the image manifest.
AnswerB

Docker builds images as a stack of immutable layers. Deleting a file in a subsequent layer only adds a whiteout marker; the original layer still contains the file's bytes and can be extracted by anyone with the image. This is why secrets copied into any layer remain recoverable, directly explaining the leak the engineer observed.

Why this answer

Container images are composed of immutable layers, one per Dockerfile instruction. Removing a file in a later RUN step only records a deletion in that new layer; the bytes remain in the earlier layer and can be recovered by extracting the image. Secrets must therefore be injected at runtime via secrets management, never copied into any layer.

Exam trap

The trap here is believing that deleting a file in a later Dockerfile instruction removes it from the image, when layer immutability preserves the original bytes.

323
Multi-Selectmedium

A security administrator is hardening a Linux server and needs to ensure that user passwords meet complexity requirements and are stored securely. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Disable password aging by setting PASS_MAX_DAYS to 99999.
B.Store passwords in /etc/passwd instead of /etc/shadow to simplify management.
C.Ensure /etc/shadow is readable only by root and the shadow group.
D.Set the password hashing algorithm to SHA-256 in /etc/login.defs.
E.Configure PAM with pam_pwquality to enforce minimum length and character classes.
AnswersC, E

/etc/shadow stores password hashes and must be protected from unauthorized reading. Setting permissions to 640 or 000 with root ownership prevents non-privileged users from accessing hashes, mitigating offline cracking. This is a fundamental security measure for secure password storage. It complements complexity policies by protecting the stored hashes.

Why this answer

To enforce password complexity, the administrator should configure pam_pwquality, which provides configurable checks for length, character classes, and dictionary words. To secure password storage, the administrator must ensure /etc/shadow is properly permissioned so that only root and the shadow group can read it, protecting hashes from unauthorized access. Other options either weaken security or do not address the specific requirements.

Exam trap

The trap here is thinking that password hashing algorithm changes alone enforce complexity, when complexity is actually handled by PAM modules like pam_pwquality.

324
MCQeasy

A network engineer is documenting how a workstation obtains an IPv4 address on a corporate LAN. The engineer observes the workstation broadcasting a request, receiving a unicast offer from a server, broadcasting a formal request for that address, and finally receiving an acknowledgment. The engineer must record which transport protocol and ports this address-assignment exchange uses. Which combination correctly describes the exchange?

A.UDP ports 53 and 54, because the address server acts as a directory service.
B.ICMP type 4 and type 5 messages, because routers advertise addresses to local hosts.
C.TCP ports 67 and 68, because address assignment requires a reliable connection.
D.UDP ports 67 and 68, with the server listening on 67 and the client on 68.
AnswerD

DHCP uses UDP because the client initially has no IP address and must broadcast. The server listens on UDP port 67 and the client uses UDP port 68. The four-step DORA exchange (Discover, Offer, Request, Acknowledge) fits this model. This combination correctly matches both the transport protocol and the port assignments observed in the scenario.

Why this answer

DHCP performs address assignment over UDP, with the server on port 67 and the client on port 68, because the client must broadcast before it possesses an address. The DORA sequence (Discover, Offer, Request, Acknowledge) matches the observed broadcast request, unicast offer, broadcast request, and acknowledgment. TCP and the other listed protocols cannot provide this broadcast-based assignment.

Exam trap

The trap here is matching the well-known DHCP port numbers to TCP instead of UDP, or confusing DHCP with DNS based on similar client-server roles.

325
MCQmedium

An organization requires that all employee MacBook Pro devices prevent unauthorized modifications to the system kernel. Which macOS security feature should the administrator focus on to ensure that only Apple-signed code executes at the kernel level?

A.FileVault 2
B.Gatekeeper
C.System Integrity Protection (SIP)
D.XProtect
AnswerC

System Integrity Protection restricts the root user from modifying protected locations like /System, /bin, and /usr. By enforcing signed kernel extensions and preventing unauthorized modifications to system processes, it directly protects the kernel integrity, ensuring that only trusted, Apple-approved code can operate at the system core level.

Why this answer

System Integrity Protection (SIP) is the macOS feature designed to restrict the root user from performing actions that could compromise system integrity. By enforcing kernel-level protection, SIP prevents malicious code from injecting into system processes or modifying protected files. Understanding SIP is critical for GSEC candidates as it represents the foundational boundary between user-space applications and sensitive kernel operations, serving as a primary defense against rootkits and low-level system tampering.

Exam trap

Candidates frequently mistake Gatekeeper or XProtect for SIP, failing to recognize that SIP is specifically the mechanism that enforces kernel-level integrity and prevents root-level modifications.

326
MCQeasy

A security administrator is reviewing the access control model used by a Windows Server 2022 domain controller. They need to ensure that when a user logs on, the system evaluates the user's group memberships and generates a data structure that is used for all subsequent access checks. Which component is responsible for this?

A.Group Policy Object (GPO)
B.Security Descriptor
C.Access Token
D.Security Identifier (SID)
AnswerC

The access token is created during logon and contains the user's SID, group SIDs, and privileges. It is attached to every process or thread the user runs and is used by the Security Reference Monitor to perform access checks against objects' security descriptors. Thus, it is the data structure that holds the security context for access evaluation.

Why this answer

During interactive or network logon, the Local Security Authority (LSA) authenticates the user and creates an access token. This token includes the user's SID, the SIDs of all groups the user belongs to, and any privileges assigned. The token is then used by the Security Reference Monitor for all access checks against securable objects.

Therefore, the access token is the correct component.

Exam trap

The trap here is confusing the access token with the Security Descriptor, which is attached to objects, not users, and is used during access checks but is not generated at logon.

327
MCQeasy

A web developer is implementing a new session management system and wants to ensure that session cookies are not accessible via JavaScript to mitigate cross-site scripting (XSS) attacks. Which cookie attribute should be set?

A.SameSite
B.Domain
C.HttpOnly
D.Secure
AnswerC

The HttpOnly attribute instructs the browser to prevent client-side scripts from accessing the cookie. This directly mitigates XSS attacks that attempt to steal session cookies via document.cookie. When set, the cookie is only accessible to the server, not JavaScript. This is the correct attribute to use for the described requirement.

Why this answer

The HttpOnly attribute is specifically designed to prevent client-side scripts from accessing cookies. By setting HttpOnly, the cookie is protected from theft via XSS attacks that execute JavaScript in the victim's browser. The other attributes serve different purposes: Secure ensures HTTPS transmission, SameSite mitigates CSRF, and Domain controls cookie scope.

Only HttpOnly directly addresses the requirement.

Exam trap

The trap here is confusing the Secure attribute with HttpOnly; Secure protects transmission, not JavaScript access.

328
MCQmedium

A security administrator wants to enable PowerShell script block logging on a Windows 10 workstation to capture suspicious script content. The administrator runs `Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'`. Which registry value should be configured to enable this feature?

A.EnableTranscripting (DWORD) set to 1
B.EnableScriptBlockInvocationLogging (DWORD) set to 1
C.EnableScriptBlockLogging (DWORD) set to 1
D.EnableModuleLogging (DWORD) set to 1
AnswerC

The EnableScriptBlockLogging registry value, when set to 1, enables script block logging. This causes PowerShell to log script blocks to the Windows Event Log, specifically Event ID 4104. This is the correct value to configure under the ScriptBlockLogging key. It is a common security control to detect malicious scripts and is often set via Group Policy or manually.

Why this answer

Script block logging is enabled by setting the EnableScriptBlockLogging DWORD value to 1 under the ScriptBlockLogging registry key. This logs script blocks to Event ID 4104, providing visibility into potentially malicious scripts. Other logging features like module logging and transcription serve different purposes and are configured elsewhere.

Exam trap

The trap here is confusing script block logging with module logging or transcription, or selecting a similarly named value like EnableScriptBlockInvocationLogging.

329
MCQhard

A software vendor distributes signed firmware updates to customers. During an incident review, an analyst discovers that an attacker who obtained the vendor's code-signing private key was able to produce updates that passed signature verification on customer devices. The vendor wants to redesign the signing process so that compromise of a single signing key no longer allows an attacker to forge valid updates. Which change best achieves this goal?

A.Increase the RSA key size from 2048 to 4096 bits.
B.Require each update to be signed by a threshold of multiple independent keys.
C.Publish the firmware hashes to a public transparency log.
D.Switch the signature algorithm from RSA to ECDSA with P-256.
AnswerB

Threshold signing requires a quorum of distinct private keys, often held in separate HSMs or by separate administrators, to produce one valid signature. An attacker who compromises a single key cannot meet the threshold, so forged updates fail verification. This directly addresses the goal of making single-key compromise insufficient, and it is supported by standards such as FIPS 186-5 and common HSM quorum configurations.

Why this answer

Threshold signing distributes the signing capability across multiple independent keys so that no single compromised key can produce a valid signature. Increasing key size, changing to ECDSA, or adding a transparency log all leave a single key capable of forging updates. Only requiring a quorum of keys changes the trust model so that one stolen key is insufficient.

Exam trap

The trap here is conflating stronger cryptography with stronger key custody; a bigger key or a modern algorithm cannot protect against an attacker who already holds the private key.

330
MCQmedium

Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?

A.Cross-Site Request Forgery (CSRF)
B.Cross-Site Scripting (XSS) session theft
C.Man-in-the-Middle (MitM) interception
D.SQL Injection (SQLi)
AnswerB

HttpOnly prevents JavaScript from reading the cookie content. In an XSS scenario, an attacker typically tries to exfiltrate the session cookie to an external server. With the HttpOnly attribute, the browser rejects requests from scripts to read the cookie, effectively neutralizing this specific theft vector during an injection.

Why this answer

The HttpOnly flag is a vital defense against session hijacking via XSS. When this flag is enabled, the browser prevents client-side scripts, such as JavaScript, from accessing the cookie via the document.cookie object. If an attacker successfully executes an XSS attack, they cannot steal the session cookie, thereby preventing them from impersonating the user's session.

This is a core defense-in-depth practice for protecting authentication tokens in modern web applications.

Exam trap

Candidates often confuse the HttpOnly flag with the Secure flag, incorrectly believing HttpOnly prevents interception over unencrypted networks rather than preventing script access.

331
MCQhard

A healthcare organization uses a public cloud IaaS provider to host electronic health records (EHRs). The security team must ensure that data at rest is encrypted and that the cloud provider cannot access the plaintext. Which approach best meets this requirement?

A.Enable server-side encryption with provider-managed keys and enforce TLS for data in transit.
B.Use provider-managed encryption keys with automatic rotation.
C.Implement client-side encryption with customer-managed keys stored on-premises.
D.Use a cloud access security broker (CASB) to encrypt data before it reaches the cloud.
AnswerC

Client-side encryption with customer-managed keys stored on-premises ensures that data is encrypted before it leaves the organization's control, and the cloud provider never has access to the keys. This satisfies the requirement that the provider cannot access plaintext, as the provider only stores encrypted blobs. It also aligns with compliance requirements for protecting sensitive health information.

Why this answer

Client-side encryption with customer-managed keys stored on-premises ensures that the cloud provider never has access to the encryption keys or plaintext data. Provider-managed keys leave the provider with decryption capability, failing the requirement. Other options like CASB or server-side encryption do not fully prevent provider access to plaintext.

Exam trap

The trap here is assuming that server-side encryption with provider-managed keys prevents the provider from accessing data, but the provider holds the keys and can decrypt.

332
MCQmedium

A security analyst at a financial firm discovers that a user's workstation is executing a malicious macro embedded in a Microsoft Word document. The macro is attempting to download a second-stage payload from a remote server. The analyst wants to prevent this specific type of attack from succeeding on other workstations while allowing legitimate macros to run. Which of the following is the MOST effective mitigation?

A.Disable all macros without notification in the Trust Center settings for all Office applications.
B.Deploy a web proxy that blocks all outbound traffic to unknown domains to prevent payload download.
C.Implement an application whitelist that only allows signed Microsoft Office executables to run.
D.Enable Microsoft Office's 'Block macros from running in Office files from the Internet' policy via Group Policy.
AnswerD

This policy, available in Office 2016 and later, blocks macros in files that originate from the Internet (e.g., downloaded from email or web). It directly addresses the scenario where a user opens a malicious document from an external source, while still allowing macros in trusted internal files. It is a targeted, effective control that does not require disabling macros entirely.

Why this answer

The 'Block macros from running in Office files from the Internet' policy is specifically designed to mitigate macro-based malware delivered via email or web downloads. It uses Mark-of-the-Web to identify files from untrusted sources and blocks macro execution while allowing macros in trusted local files. This balances security with usability, making it the most effective targeted mitigation for the described attack.

Exam trap

The trap here is assuming that disabling all macros is the only way to stop macro malware, overlooking the more granular 'Block macros from the Internet' policy that preserves legitimate macro functionality.

333
MCQhard

A network architect is designing a new data center fabric that must support a large number of tenants with strict isolation requirements. The design uses a spine-leaf topology with VXLAN overlay. The architect must ensure that broadcast, unknown unicast, and multicast (BUM) traffic from one tenant never reaches another tenant's virtual tunnel endpoints (VTEPs). Which mechanism should be implemented to meet this requirement?

A.Enable IGMP snooping on all leaf switches so multicast traffic is pruned to only the ports that requested the group.
B.Configure a unique anycast gateway MAC address on each leaf switch to prevent hosts from roaming between tenants.
C.Use a separate physical spine-leaf fabric for each tenant and interconnect them with a firewall.
D.Assign each tenant a unique VXLAN Network Identifier (VNI) and map each VNI to a separate bridge domain on every leaf switch.
AnswerD

VXLAN uses the 24-bit VNI to identify a Layer 2 segment. Mapping each tenant to a distinct VNI and bridge domain ensures that BUM traffic is scoped to that tenant's segment only. VTEPs flood BUM frames only to other VTEPs that have the same VNI, so one tenant's broadcast domain cannot reach another tenant's endpoints. This directly satisfies the isolation requirement.

Why this answer

In a VXLAN overlay, tenant isolation is achieved by assigning each tenant a distinct VNI and bridge domain. VTEPs flood BUM traffic only within the same VNI, so segments remain logically separate even though they share the same physical spine-leaf fabric. IGMP snooping, anycast gateway MACs, and separate physical fabrics do not provide the required per-tenant Layer 2 boundary in a shared overlay.

Exam trap

The trap here is thinking that multicast optimization or gateway redundancy features provide tenant isolation, when isolation in VXLAN is fundamentally a function of the VNI and bridge domain mapping.

334
Multi-Selectmedium

A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)

Select 2 answers
A.Enriching events with contextual data, such as asset criticality, user identity, and geolocation, from external sources.
B.Configuring the SIEM to drop logs that do not match the expected format to reduce noise.
C.Mapping vendor-specific log fields to a common schema, such as the Splunk Common Information Model (CIM).
D.Storing all raw logs indefinitely in their original format without normalization.
E.Increasing the SIEM's indexing speed by disabling timestamp recognition on all logs.
AnswersA, C

Enrichment adds context to raw events, enabling more accurate correlation and prioritization. For example, knowing that a server is critical or that a user is a privileged administrator helps analysts assess the severity of an alert. Geolocation can highlight impossible travel. This task is essential for effective alerting because it reduces false positives and helps focus on high-risk activities. It complements normalization by adding business-relevant metadata.

Why this answer

Normalization and enrichment are critical for SIEM effectiveness. Mapping fields to a common schema like the Splunk CIM ensures consistent field names for correlation. Enriching with context such as asset criticality and geolocation improves alert accuracy and prioritization.

These two tasks together enable the SIEM to correlate events across diverse sources and generate meaningful alerts.

Exam trap

The trap here is thinking that dropping non-conforming logs or storing raw logs indefinitely is part of normalization and enrichment, when those actions actually hinder effective correlation.

335
MCQhard

A media company uses a serverless function to process uploaded images. The function is triggered by object storage events and writes results to a database. A security review finds that the function's execution role grants full administrative access to all cloud services. Which action best applies the principle of least privilege to this serverless workload?

A.Enable function-level concurrency limits to prevent runaway executions.
B.Move the function's credentials into environment variables encrypted with a customer-managed key.
C.Configure the function to run inside a virtual private cloud with restrictive security groups.
D.Replace the administrative role with a role scoped to the specific object storage bucket and database table the function uses.
AnswerD

Scoping the execution role to only the bucket and table the function needs removes the broad administrative permissions and limits the blast radius if the function is compromised. This directly implements least privilege for the serverless workload while preserving its required read and write operations.

Why this answer

Least privilege for a serverless function means its execution role should grant only the actions and resources required to do its job. Replacing an administrative role with one scoped to the specific bucket and database table removes unnecessary permissions and reduces the impact of compromise. Credential encryption, concurrency limits, and network restrictions do not shrink the role's effective permissions.

Exam trap

The trap here is treating credential protection or network controls as equivalent to least privilege, when the finding is specifically about an execution role that grants far more permissions than the workload needs.

336
MCQhard

A financial services firm runs containerized workloads on a managed Kubernetes service. An auditor asks how the firm can ensure that only container images that passed its internal vulnerability scan can be deployed to the cluster. Which control should the firm implement?

A.Set the imagePullPolicy to Always on every container manifest.
B.Configure the container runtime to run all pods as non-root users.
C.Configure a network policy that denies egress from all namespaces.
D.Enable a Kubernetes admission controller that validates image signatures or scan attestations.
AnswerD

An admission controller such as one backed by Sigstore Cosign or a policy engine can reject pod creation unless the image carries a valid signature or attestation from the firm's scanner. This enforces the requirement at the API server before scheduling, ensuring only scanned, approved images reach the cluster.

Why this answer

Admission control is the enforcement point in Kubernetes that can evaluate an image's signature or scan attestation before a pod is scheduled. By requiring a valid signature or attestation from the internal scanner, the firm guarantees that only images that passed its process can be deployed. Network policies, pull policies, and non-root settings affect runtime behavior but not image admissibility.

Exam trap

The trap here is confusing image pull behavior or runtime hardening with admission control, when only an admission controller can reject a pod before it is scheduled based on image provenance.

337
Multi-Selectmedium

A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)

Select 2 answers
A.Enforcing a password complexity policy for all database accounts
B.Deploying host-based intrusion detection system (HIDS) agents on database servers
C.Implementing database activity monitoring (DAM) to log and alert on suspicious SQL queries
D.Implementing full-disk encryption on the database server
E.Configuring a next-generation firewall to block outbound traffic from the database server
AnswersB, C

HIDS agents monitor host-level activity such as file changes, process execution, and unauthorized access attempts, providing visibility into attacker actions on the database server. This directly addresses the lack of host-based logging and would help detect similar credential-based intrusions. It adds a detective layer at the host level, complementing network controls.

Why this answer

The breach exploited stolen credentials to access a database server, and the gaps were lack of host-based logging and database activity monitoring. HIDS agents provide host-level visibility into attacker actions, while DAM logs and alerts on suspicious database queries. Together they create detective controls that would likely have identified the unauthorized access.

The other options are preventive or confidentiality controls that do not address the detection gap.

Exam trap

The trap here is focusing on preventive controls like password policies or encryption when the scenario explicitly asks for detection improvements after a credential-based breach.

338
MCQmedium

A security analyst is reviewing the update history of a Windows 10 Enterprise device managed by Windows Update for Business (WUfB). The analyst notices that a critical security update was installed 30 days after its release, even though no deferral policies were configured. Which factor is the most likely cause for the delayed installation?

A.The device was configured to use a Windows Update for Business deferral for quality updates.
B.The update was blocked by a Windows Defender Application Control (WDAC) policy.
C.The device was offline or in sleep mode during the update's initial release period.
D.The update was not approved in Windows Server Update Services (WSUS).
AnswerC

Windows Update for Business schedules updates based on device activity and connectivity. If the device is offline, in sleep mode, or not connected to the internet during the update's release, it will not download and install the update until it becomes active and connected. This can cause delays even without deferral policies. The 30-day delay suggests the device missed the initial release window due to being offline or inactive, which is a common cause in WUfB environments.

Why this answer

The most likely cause is that the device was offline or inactive during the update's release. WUfB does not force immediate installation; it relies on the device being on and connected to download and install updates. Without deferral policies, updates are offered as soon as they are released, but installation depends on device availability.

A 30-day delay aligns with a device that was not used or connected for an extended period, after which it received the update upon becoming active.

Exam trap

The trap here is assuming that without deferral policies, updates install immediately, overlooking device availability and connectivity requirements.

339
MCQmedium

A security analyst is reviewing a compromised Linux web server. The attacker escalated to root and then ran a script that unlinked the file /var/log/auth.log to hide their tracks. The analyst runs `lsof | grep auth.log` and sees the file is still open by the rsyslogd process, but `ls /var/log/auth.log` reports that the file does not exist. Which of the following best explains why the file content is still accessible through the open file descriptor?

A.The Linux kernel maintains the inode and data blocks until the last open file descriptor referencing the inode is closed, even after the directory entry is removed.
B.The rsyslogd process has the file memory-mapped with mmap, so the page cache keeps a copy that ls can still resolve by inode lookup.
C.The file was moved to a hidden directory by the attacker, and lsof is resolving the path from the process's current working directory rather than the real inode.
D.The ext4 filesystem journals file deletions, and lsof reads the journal to reconstruct the file contents until the journal is overwritten by subsequent writes.
AnswerA

On Linux, unlinking a file only removes the directory entry (the name-to-inode link). The inode's link count drops, but the inode and its data blocks are not reclaimed while any process still holds an open file descriptor. The analyst can recover the content through /proc/<pid>/fd/<n>, which is why the data remains accessible to rsyslogd until it is restarted or closes the descriptor.

Why this answer

When a file is unlinked on Linux, the directory entry is removed but the inode persists as long as a process holds an open file descriptor. rsyslogd keeps auth.log open for writing, so the kernel cannot free the inode or data blocks. The analyst can recover the contents via /proc/<rsyslogd-pid>/fd/<descriptor>, even though the pathname no longer resolves. Restarting rsyslogd would close the descriptor and finally reclaim the inode.

Exam trap

The trap here is assuming that deleting a file immediately frees its disk space and destroys its contents, when in fact an open file descriptor keeps the inode alive until the last handle is closed.

340
MCQmedium

A security administrator is hardening a Windows Server 2022 domain controller. They need to ensure that NTLM authentication is not used for any domain accounts and that only Kerberos is used. Which Group Policy setting should they configure?

A.Network security: Restrict NTLM: NTLM authentication in this domain
B.Network security: LAN Manager authentication level
C.Network security: Minimum session security for NTLM SSP based (including secure RPC) servers
D.Network security: Configure encryption types allowed for Kerberos
AnswerA

This setting allows you to deny NTLM authentication for domain accounts. When set to 'Deny all,' it blocks NTLM authentication requests for domain accounts, forcing Kerberos. This directly addresses the scenario by preventing NTLM use entirely within the domain.

Why this answer

The 'Network security: Restrict NTLM: NTLM authentication in this domain' policy explicitly controls NTLM usage for domain accounts. Setting it to 'Deny all' blocks NTLM authentication and forces Kerberos, which is the desired outcome. Other settings may harden NTLM or Kerberos but do not disable NTLM entirely.

Exam trap

The trap here is confusing settings that harden NTLM with settings that actually block NTLM authentication.

341
Multi-Selecthard

A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)

Select 2 answers
A.Assign the 'Log on as a service' right to all domain users to ensure that any service can start without interruption.
B.Configure all services to run under the Local System account to simplify management and ensure they have the necessary privileges.
C.Enable the 'Store passwords using reversible encryption' policy for all service accounts to allow easy recovery of passwords if needed.
D.Implement a policy to regularly audit service accounts for excessive privileges and remove unnecessary rights, such as 'Act as part of the operating system' or 'Debug programs'.
E.Deploy Group Managed Service Accounts (gMSAs) for services that require domain authentication, ensuring automatic password management and eliminating the need for manual password updates.
AnswersD, E

Regular auditing of service account privileges helps identify and remediate excessive permissions. Rights like 'Act as part of the operating system' and 'Debug programs' are highly sensitive and should be restricted to only those accounts that absolutely require them. Removing unnecessary rights reduces the potential impact if an account is compromised. This option is correct because it enforces least privilege and helps prevent privilege escalation, aligning with hardening best practices.

Why this answer

The correct actions are to deploy gMSAs for domain-authenticated services and to audit and reduce service account privileges. gMSAs provide automatic password management and reduce credential theft risk. Auditing privileges ensures least privilege and removes dangerous rights. The other options either increase risk by granting excessive privileges or weaken security through reversible encryption or overly broad logon rights.

Exam trap

The trap here is thinking that simplifying service account management by using Local System or granting broad logon rights improves security, when in fact it expands the attack surface.

342
MCQhard

Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?

A.Channel 1 selection is a performance concern.
B.WPS enabled allows for PIN-based brute-force attacks.
C.WPA2-PSK is insufficient for modern enterprise needs.
D.Management Frame Protection is disabled.
AnswerB

WPS (Wi-Fi Protected Setup) is highly insecure because the PIN validation process is flawed. Attackers can brute-force the PIN in small segments, eventually retrieving the network PSK. This vulnerability exists regardless of how strong the actual WPA2 password is, making it a critical security risk for any network.

Why this answer

The exhibit shows WPS enabled on a WPA2-PSK network. WPS is notoriously vulnerable to brute-force attacks against its 8-digit PIN, which can be cracked in hours, revealing the underlying WPA2 passphrase. Disabling WPS is a standard security requirement because the protocol's design flaw allows for efficient recovery of the network key regardless of the passphrase's complexity, rendering the PSK security model entirely ineffective.

Exam trap

Candidates often confuse WPS vulnerabilities with standard WPA2 passphrase complexity issues, incorrectly assuming a strong pre-shared key mitigates an enabled Wi-Fi Protected Setup PIN flaw.

343
MCQmedium

When investigating a Windows system, which file system feature is responsible for recording the file metadata including timestamps for created, modified, and accessed (MACE) times?

A.Registry hives
B.Master File Table (MFT)
C.Event Logs
D.Prefetch files
AnswerB

The MFT is a relational database that acts as the backbone of NTFS. It stores the metadata for every file and folder on the partition, including the primary timestamps (Standard Information and File Name attributes) used for forensic timeline analysis and detecting file modification or deletion events.

Why this answer

The Master File Table (MFT) is the core of the NTFS file system. Every file on an NTFS volume has at least one entry in the MFT. These entries contain the MACE times, which are critical for building a timeline of events.

If these times are altered, it often indicates anti-forensic activity, making the MFT the primary source for verifying file history and integrity during an investigation.

Exam trap

Candidates often confuse file system metadata structures with application logs or registry hives when identifying where MACE timestamps are natively recorded on NTFS volumes.

344
MCQhard

Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?

A.Reboot the workstation immediately
B.Isolate the workstation from the network
C.Delete the PowerShell process
D.Update the antivirus definitions
AnswerB

Isolating the host prevents the attacker from issuing further commands or exfiltrating data, effectively containing the threat. By cutting the network path, you stop the malicious script from reaching its destination without destroying the volatile memory evidence needed to identify the full scope of the attack activity.

Why this answer

The exhibit shows base64 encoded PowerShell execution, commonly used for malicious script downloads. Immediate containment requires isolating the endpoint from the network to prevent further outbound connections to C2 servers. By severing the network connection, responders prevent the attacker from executing additional instructions, exfiltrating data, or establishing secondary persistence mechanisms while the forensic investigation proceeds offline.

Exam trap

Candidates often suggest running a malware scan or deleting the script, which allows the attacker to maintain C2 connectivity while the responder works, failing to prioritize immediate containment.

345
MCQmedium

A security administrator needs to ensure that a newly created script, 'cleanup.sh', can only be executed by the file owner, while preventing any other users from reading or writing the file. Which command achieves this configuration?

A.chmod 777 cleanup.sh
B.chmod 755 cleanup.sh
C.chmod 700 cleanup.sh
D.chmod 600 cleanup.sh
AnswerC

The 700 octal mode provides full control to the owner (rwx) and explicitly denies all access to group and other users. This ensures that only the file owner can interact with the script, effectively mitigating risks associated with unauthorized execution or inspection of sensitive administrative tasks on the Linux system.

Why this answer

The chmod command with the octal value 700 applies read, write, and execute permissions exclusively to the owner (7), while setting no permissions for the group (0) and others (0). This follows the principle of least privilege by isolating the script's execution to the authorized user. Restricting access is critical in Linux security to prevent unauthorized execution of potentially sensitive maintenance utilities by standard users or attackers.

Exam trap

Candidates often mix up octal permission positions or confuse read/write/execute values, mistakenly selecting 777 or 007 because they fail to map the owner-only requirement properly.

346
Multi-Selectmedium

A security analyst is responding to a confirmed malware infection on a critical server. The analyst has already contained the infection by isolating the server from the network. According to the incident handling process, which TWO actions should the analyst perform during the eradication phase? (Choose two.)

Select 2 answers
A.Conduct a post-incident review to document lessons learned.
B.Apply security patches and updates to the server's operating system and applications.
C.Restore the server from a known good backup taken before the infection.
D.Identify and remove all malicious files and processes from the server.
E.Monitor network traffic for signs of re-infection.
AnswersB, D

Applying security patches and updates is part of eradication because it addresses the vulnerability that may have been exploited. Even if the malware is removed, without patching, the server remains vulnerable to re-infection. Eradication involves not only removing the threat but also eliminating the root cause. Patching is a preventive measure that strengthens the system against future attacks.

Why this answer

The correct actions are to identify and remove all malicious files and processes, and to apply security patches and updates. Eradication is the phase where the threat is eliminated from the environment. This includes removing malware and addressing the vulnerability that allowed the infection.

Patching ensures that the same attack vector cannot be used again. Restoring from backup, post-incident review, and monitoring are associated with recovery or post-incident activities, not eradication.

Exam trap

The trap here is confusing recovery actions like restoring from backup with eradication actions, which focus on removing the threat and its root cause.

347
MCQhard

During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?

A.Deploying a traditional static packet-filtering firewall with inbound rule sets.
B.Enforcing strict Egress Filtering policies on internal router and firewall interfaces.
C.Configuring port security on all access layer switch ports to limit MAC addresses.
D.Implementing WPA3 Enterprise wireless security across all corporate access points.
AnswerB

Egress filtering inspects and blocks outbound traffic at router and firewall interfaces, permitting only approved ports and protocols. This directly prevents the unexpected outbound administrative channels observed, satisfying the requirement to restrict unauthorised outbound communication at the network perimeter.

Why this answer

Egress filtering inspects and restricts outbound traffic leaving the internal network to ensure only authorized business protocols and ports can traverse the perimeter. Implementing strict egress filtering prevents compromised hosts from communicating with external command-and-control servers or exfiltrating data via unauthorized ports.

Exam trap

Candidates often select internal host-based firewalls or ingress filtering, forgetting that outbound traffic requires egress filtering at the perimeter to stop exfiltration.

348
MCQmedium

An enterprise network administrator needs to isolate a new public-facing web application so that a compromise of the web server does not immediately expose the internal corporate database and directory services. Which network architecture design pattern provides the most effective defense for this scenario?

A.Deploying the web server on the internal corporate VLAN alongside domain controllers to streamline administrative access and reduce network latency.
B.Implementing a flat network topology utilizing unmanaged switches to maximize throughput and simplify routing tables for incoming web traffic.
C.Configuring a demilitarized zone (DMZ) flanked by firewalls to separate public-facing web assets from internal network resources.
D.Connecting the web server directly to the outer provider edge router via a public bridge to bypass internal switching bottlenecks.
AnswerC

A demilitarized zone architecture establishes a dedicated buffered network segment protected by firewalls. This design ensures that traffic from the internet can only reach designated public services while strictly prohibiting direct connections from the perimeter into the trusted internal network.

Why this answer

Deploying a demilitarized zone (DMZ) creates a buffered network segment between the untrusted public internet and the trusted internal corporate network. By placing the web server in the DMZ and utilizing firewalls to restrict inbound and outbound traffic flows, administrators successfully contain potential breaches. This defensive architecture stops attackers from pivoting directly into sensitive internal resources following an initial web application compromise.

Exam trap

Examinees often select internal network segmentation or a standard virtual local area network without realizing that a public-facing web tier specifically requires a buffered DMZ architecture.

349
MCQmedium

An organization implements firewalls, intrusion detection systems, and disk encryption. Which principle best describes the deployment of multiple, overlapping security controls to protect critical assets?

A.Least Privilege
B.Security through Obscurity
C.Defense in Depth
D.Fail-Safe Defaults
AnswerC

Defense in depth is an information security strategy that integrates multiple layers of security controls throughout an IT system. Its primary goal is to protect data by ensuring that if an attacker bypasses one defense, subsequent layers remain to prevent unauthorized access or minimize the overall impact.

Why this answer

Defense in depth uses layered security to ensure that if one control fails, others remain to mitigate risk. This strategy is critical because no single security measure is foolproof against sophisticated attackers. By diversifying controls across network, host, and data layers, the organization increases the attacker's workload and reduces the probability of a successful breach, ensuring that failures in one area do not lead to a catastrophic compromise of sensitive information.

Exam trap

Candidates often mistake this principle for least privilege or redundancy, confusing operational system fault tolerance with security-focused control layering.

350
MCQmedium

An organization is deploying an automated incident response tool. Which requirement is most important to ensure the tool's effectiveness during a high-severity security incident?

A.Integration with the social media monitoring platform
B.Integration with external threat intelligence feeds
C.Pre-defined and validated response playbooks
D.Unlimited cloud storage for log retention
AnswerC

Automated response tools rely on playbooks to determine actions. If these are not pre-defined and tested, the tool could inadvertently disrupt business operations. Validated playbooks ensure the automation performs safe and effective containment actions without requiring manual intervention, which is essential during a fast-moving, high-severity security incident.

Why this answer

Automated tools must have clear, pre-defined playbooks. If automation is used without strict, validated logic, it may trigger unintended consequences, such as locking out critical production services or deleting valid data during an active attack. Effective automation requires accurate context to prevent the incident response tool from causing more operational downtime than the actual security threat it is designed to mitigate during a crisis.

Exam trap

Candidates often prioritize the 'speed' of the tool over the 'accuracy' of the playbooks, missing that unvalidated automation can cause catastrophic self-denial-of-service during a critical incident.

351
MCQmedium

A company uses Microsoft Entra ID (formerly Azure AD) and has a critical line-of-business application that authenticates users via SAML 2.0. The security team wants to enforce multi-factor authentication (MFA) for this application without affecting other applications. They have Entra ID P1 licenses. What is the most appropriate way to achieve this?

A.Set up a per-application MFA setting in the Enterprise Applications blade by enabling the 'Require multi-factor authentication' option for the specific application.
B.Create a new authentication method policy that restricts MFA to only the users who need access to the application.
C.Configure a Conditional Access policy that targets the specific application and requires MFA for all users.
D.Enable security defaults in Entra ID, which will automatically enforce MFA for all users and applications.
AnswerC

Conditional Access policies in Entra ID allow granular control over authentication requirements, including the ability to target specific cloud applications. By creating a policy that includes the line-of-business application as the target and requires MFA, the security team can enforce MFA only for that app. This approach leverages Entra ID P1 features and does not affect other applications. It is the recommended method for per-application MFA enforcement.

Why this answer

Conditional Access policies in Entra ID allow administrators to enforce MFA for specific applications and users. This is the most granular and appropriate method when you have Entra ID P1 licenses. Security defaults apply tenant-wide, the per-application MFA setting is deprecated, and authentication method policies do not enforce MFA per application.

Therefore, the correct solution is to create a Conditional Access policy targeting the line-of-business application.

Exam trap

The trap here is confusing tenant-wide MFA enforcement methods like security defaults with application-specific enforcement, which requires Conditional Access.

Page 4

Page 5 of 5

All pages