
GIAC Foundational Cybersecurity Technologies
Domain 5Objective 1
Security Concepts GFACT Practice Questions (Page 5)
Part of the Security Fundamentals domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 6–9 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 21–25
- 21
A security researcher discovers a vulnerability in a widely used web browser. The researcher wants to disclose the vulnerability responsibly. Which action best aligns with ethical and legal standards for vulnerability disclosure?
Select an answer first - 22
A security researcher is asked to test the security of a government website. The researcher does not have written authorization but believes the test is for the public good. The researcher performs a port scan and identifies a vulnerability. What is the most appropriate action?
Select an answer first - 23
What is the key ethical principle that distinguishes ethical hacking from malicious hacking?
Select an answer first - 24
A security analyst is investigating a suspected data breach. The analyst finds that an attacker modified a system log file to hide their activities. Which security property was violated?
Select an answer first - 25
In a typical secure email scenario, which key would a sender use to encrypt a message so that only the intended recipient can read it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.