
GIAC Foundational Cybersecurity Technologies
Domain 5Objective 1
Security Concepts GFACT Practice Questions (Page 3)
Part of the Security Fundamentals domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 6–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 11–15
- 11
A security analyst discovers that an employee, without authorization, used a publicly available exploit to test the company's own web server. The employee did not cause any damage and reported the vulnerability to the IT team. Which statement best describes the ethical and legal status of this action?
Select an answer first - 12
In cryptography, what is the term for the original, readable data that is input into an encryption algorithm?
Select an answer first - 13
A security engineer needs to ensure that a configuration file is not modified during transmission. The file does not need to be kept secret. Which cryptographic technique should be used?
Select an answer first - 14
A database administrator needs to store user passwords in a way that allows the system to verify a password at login without storing the plaintext password. The administrator also wants to ensure that two users with the same password do not have the same stored value. Which technique should the administrator use?
Select an answer first - 15
During which phase of an attack does the attacker typically establish a backdoor or other mechanism to maintain access?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.