
GIAC Critical Controls Certification
Domain 6Objective 2
Email and Web Browser Protections GCCC Practice Questions (Page 5)
Part of the Application and Network Security domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~9–14 in this domain), expect 3–5 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
12concepts
Questions 21–25
- 21
What does DNSSEC provide to protect against DNS-based attacks?
Select an answer first - 22
A company's domain is being spoofed, and the security team wants to implement DMARC. The company sends marketing emails through a third-party service that uses a different sending domain. The team has published SPF and DKIM records for the main domain. Which DMARC policy should the team initially deploy to avoid disrupting legitimate email?
Select an answer first - 23
What is the first step in responding to an email-based security incident?
Select an answer first - 24
A financial firm's analysts need to access third-party websites that are often compromised. The firm wants to ensure that any malicious code on those sites cannot execute on the analysts' workstations. Which solution best meets this requirement?
Select an answer first - 25
A company wants to enforce a policy that blocks access to gambling sites. They have a web proxy that categorizes URLs, but some gambling sites use HTTPS and the proxy does not inspect HTTPS traffic. What is the most effective way to enforce the policy?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.