Courseiva

GSEC · topic practice

Scenario practice questions

Practise GIAC Security Essentials Scenario practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
13 questionsDomain: Scenario

What the exam tests

What to know about Scenario

Scenario questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Scenario exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Scenario questions

13 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full Scenario explanation →

A security administrator is reviewing web server logs and notices a high volume of requests with different User-Agent strings, all targeting the same URL with varying query parameters. The requests appear to be attempting to inject SQL commands. Which of the following is the most effective mitigation to prevent SQL injection in this scenario?

Question 2mediummultiple choice
Review the full routing breakdown →

A security analyst is reviewing a network diagram and sees a device placed between the internet edge router and the internal firewall. The device is described as providing network address translation and stateful connection tracking but not deep application inspection. Which device type is most consistent with this description?

Question 3mediummultiple choice
Read the full Scenario explanation →

An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?

Question 4mediummultiple choice
Read the full Scenario explanation →

A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?

Question 5mediummultiple choice
Read the full Scenario explanation →

A security administrator is hardening a Linux web server that hosts customer data. During a review of mount options, the administrator notes that the /tmp and /var/tmp directories are mounted with the 'noexec' and 'nosuid' options, but /home is not. A developer complains that scripts in /home are being executed by a scheduled process. Which action best maintains security while addressing the developer's need?

Question 6mediummultiple choice
Read the full Scenario explanation →

A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?

Question 7hardmultiple choice
Read the full Scenario explanation →

A penetration tester is examining a Windows 10 system and discovers that a recent exploit leveraged a use-after-free vulnerability in a widely used PDF reader application. The exploit successfully achieved code execution. Which of the following mitigation technologies, when enabled, would have made this exploitation significantly more difficult by randomizing the memory locations of key data structures?

Question 8easymultiple choice
Read the full Scenario explanation →

A junior administrator is setting up a shared folder on a Windows Server 2022 member server. The folder will be accessed by a group called 'SalesTeam'. The administrator wants to ensure that members of SalesTeam can read and write files, but cannot change permissions or take ownership. Which NTFS permission should the administrator assign to the SalesTeam group?

Question 9mediummultiple choice
Read the full Scenario explanation →

An enterprise network administrator needs to isolate a new public-facing web application so that a compromise of the web server does not immediately expose the internal corporate database and directory services. Which network architecture design pattern provides the most effective defense for this scenario?

Question 10easymultiple choice
Read the full Scenario explanation →

A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?

Question 11mediummultiple choice
Read the full Scenario explanation →

A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?

Question 12mediummultiple choice
Read the full Scenario explanation →

A university's research department stores controlled unclassified research data on a Windows file server. The IT team wants to implement a defense in depth control that ensures only authorized users can access the data even if they have physical access to the server room. Which of the following controls best meets this requirement?

Question 13hardmultiple choice
Read the full Scenario explanation →

A SOC uses a SIEM to monitor a fleet of Linux application servers. During an incident review, analysts discover that an attacker who obtained root on one server used the command 'shred -u -z /var/log/auth.log' after gaining access. The SIEM received no authentication events from that host for the 40-minute window in which the attacker operated, even though the agent remained online and continued forwarding other log files. Which mechanism in the log pipeline most directly explains the absence of those authentication events in the SIEM, and what is the most effective control to detect this behavior in the future?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scenario sessions

Start a Scenario only practice session

Every question in these sessions is drawn from the Scenario domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Scenario?
Scenario questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scenario questions in a focused session?
Yes — the session launcher on this page draws every question from the Scenario domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.