Courseiva
← Back to GIAC Security Essentials questions

Scenario-based practice

Troubleshooting Scenario Questions

Practise GIAC Security Essentials practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

13
scenario questions
GSEC
exam code
GIAC
vendor

Scenario guide

How to approach troubleshooting scenario questions

These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.

Quick answer

Troubleshooting Scenario Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GSEC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A SIEM administrator is troubleshooting why Windows event logs forwarded from a domain controller are not being parsed correctly. The logs are sent using the Windows Event Forwarding (WEF) subscription, but the SIEM shows raw XML instead of normalized fields. The administrator confirms that the WEF subscription is active and events are arriving. Which action should the administrator take to ensure proper parsing?

Question 2hardmultiple choice
Full question →

A security administrator is troubleshooting access issues on a Windows file server. A user, Bob, is a member of the 'Sales' group, which has 'Read & Execute' on a folder. Bob is also a member of the 'Managers' group, which has 'Full Control' on the same folder. However, Bob cannot delete files. What is the most likely cause?

Question 3hardmultiple choice
Full question →

A security administrator is troubleshooting an enterprise client that repeatedly fails to complete a major Windows feature upgrade, automatically triggering a rollback. Which built-in command-line utility should the administrator use to examine detailed migration logs, error codes, and rollback triggers?

Question 4hardmultiple choice
Read the full wireless explanation →

A security architect must ensure that hosts on a guest wireless network cannot reach any internal RFC 1918 subnets, while still allowing guests to reach the internet and a captive portal hosted internally for authentication. The design uses a wireless controller that tunnels guest traffic to a dedicated guest anchor. Which approach best enforces the requirement?

Question 5hardmulti select
Read the full VPN explanation →

A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)

Question 6mediummultiple choice
Full question →

You are troubleshooting a service startup failure on a web server. Based on the error code in the exhibit, what is the most likely cause?

Exhibit

Refer to the exhibit: {"Error": "Service did not start due to logon failure", "ErrorCode": "0x8007052e", "LogonAccount": "DOMAIN\svc_app", "Machine": "SRV-WEB-01"}
Question 7easymultiple choice
Review the full routing breakdown →

A junior administrator needs to determine the default gateway configured on a Linux server to troubleshoot outbound connectivity. Which command will display the routing table and show the default route?

Question 8easymultiple choice
Open the full VLAN trunking answer →

A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?

Question 9easymultiple choice
Full question →

A user attempts to launch a newly installed application on a macOS Monterey system, but the application fails to open with a message that it cannot be verified. The user is certain the application was downloaded from the developer's official website. Which macOS feature is responsible for this behavior?

Question 10mediummultiple choice
Full question →

A security administrator is troubleshooting a Windows 10 Enterprise device that is not receiving feature updates from Windows Update for Business. The administrator confirms that the device is connected to the network and has the correct Windows Update for Business policies applied. The administrator suspects that a Group Policy setting is overriding the Windows Update for Business configuration. Which Group Policy setting should the administrator check first?

Question 11easymultiple choice
Read the full DNS explanation →

A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?

Question 12mediummultiple choice
Full question →

A system administrator notices that a user account has 'Read' permissions to a folder but is unable to access the files within it. Which Windows security mechanism is most likely restricting the user's access despite the NTFS permission settings?

Question 13mediummultiple choice
Full question →

A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?

These GSEC practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GSEC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.