Courseiva
← Back to GIAC Security Essentials questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise GIAC Security Essentials practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GSEC
exam code
GIAC
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GSEC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

A financial institution is implementing a new access control system for its trading floor. The security team must enforce a model that supports dynamic, fine-grained access decisions based on user attributes, resource attributes, and environmental conditions such as time of day. The system must also allow for centralized policy management and auditing. Which TWO of the following access control models best fit these requirements? (Choose two.)

Question 2mediummulti select
Full question →

A retail company is deploying a large language model (LLM) based customer support assistant that has access to internal order databases through a tool-calling interface. The security team wants to reduce the risk of sensitive data being exposed through the model's responses. Which two controls best address this risk? (Choose two.)

Question 3hardmulti select
Full question →

To ensure a Linux server is protected against unauthorized physical access or boot-level modifications, which THREE security controls should be implemented?

Question 4hardmulti select
Full question →

Which TWO of the following PowerShell commands would you use to audit current local group membership and verify existing scheduled tasks on a compromised Windows server?

Question 5hardmulti select
Full question →

A software company is hardening its Linux build pipeline. The team wants to apply defense in depth controls that reduce the impact of a compromised build server. Which THREE actions best support this goal? (Choose three.)

Question 6mediummulti select
Full question →

A security team is implementing a SIEM and needs to ensure that log sources are properly normalized and enriched to support effective correlation and alerting. Which TWO of the following tasks are essential for achieving this goal? (Choose two.)

Question 7hardmulti select
Full question →

A security engineer is hardening a Windows Server 2022 environment that hosts several critical services. The engineer wants to implement measures to protect against credential theft and privilege escalation via service accounts. Which two of the following actions should the engineer take? (Choose two.)

Question 8mediummulti select
Full question →

A security analyst is investigating a macOS Monterey system that may have been compromised. The analyst wants to check for signs of malicious kernel extensions. Which TWO of the following commands or tools are most appropriate for this task? (Choose two.)

Question 9hardmulti select
Full question →

During an investigation, you discover a persistent backdoor. Which THREE actions should be included in the Eradication phase?

Question 10hardmulti select
Full question →

A security team is designing a resilient perimeter architecture to protect internal services from distributed denial of service attacks and web application exploits. Which THREE architectural components must be incorporated into this design? (Choose THREE)

Question 11hardmulti select
Full question →

Which THREE of the following are examples of how network segmentation supports the principle of defense in depth?

Question 12mediummulti select
Full question →

Which TWO of the following are primary objectives of implementing a defense in depth strategy in a corporate environment?

Question 13mediummulti select
Full question →

When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?

Question 14mediummulti select
Full question →

An IT security team is auditing Windows Update for Business configurations across a multi-site enterprise. Which TWO methods can be utilized by administrators to successfully deploy and enforce these cloud-linked update policies? (Choose TWO)

Question 15mediummulti select
Full question →

Which TWO of the following are primary functions of a Public Key Infrastructure (PKI)?

Question 16mediummulti select
Full question →

A retail company is reviewing its defense in depth strategy after a breach where an attacker used stolen credentials to access a database server. The investigation showed that the server had no host-based logging, and database activity was not monitored. Which TWO controls should be added to improve detection of similar future attacks? (Choose two.)

Question 17mediummulti select
Full question →

A security analyst is reviewing how a file encryption tool protects data at rest on employee laptops. The tool must ensure that an attacker who copies the encrypted file cannot decrypt it without also obtaining the user's passphrase, and that modification of the ciphertext is detectable. Which TWO design elements should the analyst verify are present? (Choose two.)

Question 18mediummulti select
Full question →

A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)

Question 19hardmulti select
Full question →

A company's incident response plan requires a formal lessons-learned review after a major ransomware incident. Which TWO activities are appropriate during the Post-Incident Activity phase? (Choose two.)

Question 20hardmulti select
Open the full VLAN trunking answer →

A security architect is designing a defensible network architecture for a new campus. The architect must implement controls that limit the spread of malware from an infected endpoint to other endpoints on the same VLAN. Which TWO actions should be included in the design? (Choose two.)

These GSEC practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GSEC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.