Courseiva
← Back to GIAC Security Essentials questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise GIAC Security Essentials practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
GSEC
exam code
GIAC
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related GSEC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. An investigator identifies this registry key. What is the primary purpose of this information in a forensic investigation?

Exhibit

C:\Windows\System32\config\SOFTWARE
Key: Microsoft\Windows NT\CurrentVersion\ProfileList
Value: ProfileImagePath = C:\Users\Admin
Question 2mediummultiple choice
Full question →

Refer to the exhibit. An administrator runs the provided command on a macOS device to verify the security configuration. Given the output, what is the most appropriate interpretation regarding the security posture of this endpoint?

Exhibit

csrutil status
System Integrity Protection status: enabled.
Question 3mediummultiple choice
Full question →

Refer to the exhibit. An investigator is auditing logon events. Which Event ID indicates a successful network logon (Type 3) to the machine?

Exhibit

C:\Windows\System32\winevt\Logs\Security.evtx
Question 4mediummultiple choice
Full question →

Refer to the exhibit. A network administrator configured port security on a switch interface to protect against unauthorized device connections. Based on the provided configuration snippet, what action will the switch take if a third device with an unknown MAC address connects to this port?

Exhibit

interface GigabitEthernet0/1
 switchport mode access
 switchport access vlan 50
 switchport port-security maximum 2
 switchport port-security violation shutdown
!
Question 5hardmultiple choice
Full question →

Refer to the exhibit. An administrator runs this command to generate a certificate signing request. Which security vulnerability is introduced by the inclusion of the -nodes flag in this command?

Exhibit

openssl req -new -newkey rsa:2048 -nodes -out cert.csr -keyout cert.key
Question 6mediummultiple choice
Full question →

Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?

Exhibit

{"Policy": "ApplicationControl", "Mode": "Enforce", "Rules": [{"Action": "Allow", "Path": "C:\\Program Files\\*"}, {"Action": "Deny", "Path": "C:\\Users\\*\\AppData\\*"}]}
Question 7hardmultiple choice
Study the full ACL explanation →

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

Exhibit

DENY ip any host 10.0.5.5 eq 80
PERMIT tcp 192.168.1.0 0.0.0.255 host 10.0.5.5 eq 80
PERMIT ip any any
Question 8hardmultiple choice
Read the full wireless explanation →

Refer to the exhibit. Which configuration setting poses the most significant risk to the wireless network environment?

Exhibit

AP-Config-Export: { 'ssid': 'Corp_Wifi', 'encryption': 'WPA2-PSK', 'wps_enabled': 'true', 'channel': '1', 'management_frame_protection': 'disabled' }
Question 9hardmultiple choice
Full question →

Refer to the exhibit. An analyst observes this command execution on a workstation. Which immediate action represents the most effective containment strategy?

Exhibit

Log Entry: 2023-10-12 14:22:01, SRC: 192.168.1.50, DST: 10.0.0.5, CMD: 'powershell.exe -Enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsA...'
Question 10mediummultiple choice
Full question →

Refer to the exhibit. Which type of attack is being mitigated by the application framework, and what incident phase should this alert trigger?

Exhibit

ERROR: [System.Web.HttpException]: A potentially dangerous Request.Form value was detected from the client (ctl00$MainContent$txtComment='<script>alert(1)</script>').
Question 11mediummultiple choice
Full question →

Refer to the exhibit. Which security risk does the 'HttpOnly' flag specifically mitigate?

Exhibit

HTTP/1.1 200 OK
Set-Cookie: session_id=12345; HttpOnly; Secure
Content-Type: text/html
Question 12hardmultiple choice
Full question →

Refer to the exhibit. What is the effect of the (OI)(CI) flags on the 'Finance_Users' group for the C:\Data directory?

Exhibit

icacls C:\Data /grant 'Finance_Users:(OI)(CI)M'
Question 13mediummultiple choice
Full question →

Refer to the exhibit. What is the current configuration state for auditing 'Account Logon' events based on the provided output?

Exhibit

C:\> auditpol /get /category:"Account Logon"
System audit policy
Category/Subcategory Setting
Account Logon
  Credential Validation Success and Failure
Question 14hardmultiple choice
Study the full multicast explanation →

A network architect is designing a new data center fabric that must support a large number of tenants with strict isolation requirements. The design uses a spine-leaf topology with VXLAN overlay. The architect must ensure that broadcast, unknown unicast, and multicast (BUM) traffic from one tenant never reaches another tenant's virtual tunnel endpoints (VTEPs). Which mechanism should be implemented to meet this requirement?

Question 15mediummultiple choice
Full question →

You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit: {"Error": "Service did not start due to logon failure", "ErrorCode": "0x8007052e", "LogonAccount": "DOMAIN\svc_app", "Machine": "SRV-WEB-01"}

These GSEC practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GSEC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.