Courseiva
← Back to GIAC Security Essentials questions

Scenario-based practice

Hard Difficulty Questions

Practise GIAC Security Essentials practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GSEC
exam code
GIAC
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GSEC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?

Exhibit

C:\Windows\System32\config\SOFTWARE
Key: Microsoft\Windows NT\CurrentVersion\ProfileList
Value: ProfileImagePath = C:\Users\Admin
Question 2hardmultiple choice
Full question →

A company stores backup tapes offsite. An auditor notes that the tapes contain sensitive customer data and are transported by a third-party courier. The security manager wants to ensure that a lost tape cannot expose customer information. Which control best addresses this risk?

Question 3hardmulti select
Full question →

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

Question 4hardmultiple choice
Full question →

After a major security breach, the incident response team conducts a lessons-learned meeting. The team identifies that the initial detection was delayed because log sources were not properly integrated into the SIEM. Which phase of the incident response lifecycle does this finding primarily aim to improve?

Question 5hardmultiple choice
Full question →

A security analyst is reviewing a web application's HTTP response headers and notices the following header: Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'. The analyst is concerned about the application's resilience to cross-site scripting (XSS). Which of the following best describes the security implication of this policy?

Question 6hardmultiple choice
Full question →

A healthcare provider is designing a defense in depth strategy for its electronic health record (EHR) system. The security architect proposes using a different vendor's endpoint detection and response (EDR) product, a different firewall brand, and a different SIEM platform than those used by the rest of the organization. The CIO asks why heterogeneous controls are preferred over standardizing on a single vendor. Which statement best justifies the architect's recommendation?

Question 7hardmultiple choice
Full question →

A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?

Question 8hardmulti select
Full question →

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

Question 9hardmultiple choice
Full question →

A GSEC consultant is hardening a Kubernetes cluster that runs multi-tenant workloads. A developer reports that a pod in the tenants namespace was able to read the contents of the kubelet's host filesystem at /var/lib/kubelet. The pod spec includes hostPath: {path: /var/lib/kubelet, type: Directory} under volumes and mounts it at /host. The cluster has Pod Security Admission enabled with the restricted profile enforced cluster-wide, but the tenants namespace was labeled pod-security.kubernetes.io/enforce: privileged to unblock a legacy job. Which action most directly closes this exposure?

Question 10hardmultiple choice
Full question →

A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?

Question 11hardmultiple choice
Full question →

A security analyst is investigating a suspected credential theft attack on a Windows 10 workstation. The analyst reviews the Security event log and sees Event ID 4648 (A logon was attempted using explicit credentials) occurring repeatedly for a service account. Which of the following best describes the significance of this event in the context of credential theft?

Question 12hardmultiple choice
Full question →

Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?

Question 13hardmultiple choice
Full question →

An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?

Question 14hardmultiple choice
Full question →

A security engineer is designing a password hashing scheme for a new application. The scheme must be resistant to GPU-accelerated cracking and allow for tuning of CPU and memory costs. Which hashing algorithm should the engineer choose?

Question 15hardmultiple choice
Full question →

A security analyst is examining a web application that uses JSON Web Tokens (JWT) for authentication. The analyst captures a token and notices that the header contains "alg": "none". The analyst is concerned about the security of the application. Which of the following best describes the risk associated with this token?

Question 16hardmultiple choice
Study the full virtualization explanation →

A security engineer is designing a secure enterprise environment and needs to deploy network intrusion detection sensors to monitor east-west traffic moving between virtual machines inside an internal virtualization cluster. Which deployment method ensures the sensors successfully inspect internal segment traffic without introducing a single point of failure for packet forwarding?

Question 17hardmultiple choice
Full question →

An administrator is configuring NTFS permissions on a folder named C:\Audit. The folder currently has inheritance enabled from C:\, which grants Users Read & Execute. The administrator wants to prevent members of the group Temp_Contractors from accessing the folder, but they must still be able to access other folders on the C: drive. The administrator adds an explicit Deny Full Control permission for Temp_Contractors on C:\Audit. What is the effect of this change?

Question 18hardmulti select
Full question →

Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?

Question 19hardmulti select
Full question →

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

Question 20hardmultiple choice
Full question →

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

Exhibit

openssl req -new -newkey rsa:2048 -nodes -out cert.csr -keyout cert.key

These GSEC practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GSEC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.