Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Security Essentials

GSEC

The GIAC Security Essentials (GSEC) certification validates a practitioner's hands-on capability and understanding of information security beyond simple terminology and concepts. It is designed for new InfoSec professionals, security administrators, and IT engineers who need to demonstrate fluency in crucial security paradigms and technologies. Earning GSEC proves you are qualified for hands-on roles addressing security tasks in IT systems.

1175 practice questions · Updated 2026-07-30

6Domains
26Objectives
224Concepts
1175Questions

GSEC Curriculum

Every domain, objective, and concept the GSEC exam measures.

Access Control & Password Management

7 concepts · 38 questions
  1. Access Control Models
  2. Access Control Mechanisms
  3. Password Policies
  4. Password Storage and Hashing
  5. Multi-Factor Authentication
  6. Password Management Tools
  7. Account Management

Defense in Depth

9 concepts · 55 questions
  1. Defense in Depth Principle
  2. Layered Security Controls
  3. Physical Security Layer
  4. Network Security Layer
  5. Host Security Layer
  6. Application Security Layer
  7. Data Security Layer
  8. Human Factor Layer
  9. Implementation of Defense in Depth

Security Frameworks and CIS Controls

5 concepts · 39 questions
  1. Security Frameworks Overview
  2. CIS Controls Overview
  3. CIS Controls Implementation Groups
  4. CIS Controls Structure
  5. Applying Security Frameworks

Defensible Network Architecture

8 concepts · 48 questions
  1. Defensible Network Architecture Principles
  2. Network Segmentation and Zoning
  3. Perimeter Defense
  4. Internal Network Hardening
  5. Monitoring and Logging for Defense
  6. Secure Remote Access
  7. Redundancy and High Availability
  8. Zero Trust Model Integration

Network Security Devices

13 concepts · 51 questions
  1. Network Security Devices Overview
  2. Firewalls
  3. Intrusion Detection Systems (IDS)
  4. Intrusion Prevention Systems (IPS)
  5. Unified Threat Management (UTM)
  6. Next-Generation Firewalls (NGFW)
  7. Web Application Firewalls (WAF)
  8. Virtual Private Network (VPN) Concentrators
  9. Network Access Control (NAC)
  10. Proxy Servers
  11. Load Balancers
  12. Security Information and Event Management (SIEM)
  13. Placement of Security Devices

Networking & Protocols

18 concepts · 64 questions
  1. OSI Model Layers
  2. TCP/IP Model Layers
  3. Common Network Protocols
  4. Ports and Services
  5. IPv4 Addressing
  6. IPv6 Addressing
  7. Network Devices
  8. Network Topologies
  9. Network Models (Client-Server and Peer-to-Peer)
  10. Encapsulation and De-encapsulation
  11. MAC Addressing
  12. Routing Fundamentals
  13. Network Address Translation (NAT)
  14. Subnetting and CIDR
  15. DNS Resolution
  16. DHCP Operation
  17. Wireless Networking Basics
  18. Network Security Fundamentals

Wireless Network Security

5 concepts · 40 questions
  1. Wireless Security Fundamentals
  2. Wireless Encryption Protocols
  3. Wireless Authentication Methods
  4. Wireless Attacks and Countermeasures
  5. Wireless Security Best Practices

Cryptography

7 concepts · 48 questions
  1. Symmetric Cryptography
  2. Asymmetric Cryptography
  3. Hash Functions
  4. Digital Signatures
  5. Key Management
  6. Cryptographic Protocols
  7. Cryptanalysis and Attacks

Cryptography Application

8 concepts · 42 questions
  1. Symmetric Cryptography
  2. Asymmetric Cryptography
  3. Hash Functions
  4. Digital Signatures
  5. Key Exchange and Management
  6. Public Key Infrastructure (PKI)
  7. Cryptographic Protocols
  8. Applications of Cryptography

Web Communication Security

7 concepts · 46 questions
  1. TLS/SSL Fundamentals
  2. HTTPS and Certificates
  3. Common Web Attacks
  4. Secure Web Configuration
  5. Web Security Headers
  6. Cookies and Session Management
  7. Web Application Firewalls (WAF)

Container and MacOS Security

7 concepts · 43 questions
  1. Container Security Fundamentals
  2. Container Image Security
  3. Container Runtime Security
  4. Container Orchestration Security
  5. macOS Security Architecture
  6. macOS Hardening Techniques
  7. macOS Malware and Threat Mitigation

Endpoint Security

6 concepts · 40 questions
  1. Endpoint Security Fundamentals
  2. Endpoint Threats and Attack Vectors
  3. Endpoint Protection Technologies
  4. Endpoint Hardening
  5. Endpoint Detection and Response (EDR)
  6. Endpoint Security Management

Linux Fundamentals

10 concepts · 43 questions
  1. Linux File System Hierarchy
  2. File Permissions and Ownership
  3. User and Group Management
  4. Process Management
  5. Package Management
  6. Shell Basics and Command Line
  7. System Logging and Monitoring
  8. Networking Fundamentals in Linux
  9. Security Hardening Basics
  10. Boot Process and System Initialization

Linux Security and Hardening

10 concepts · 37 questions
  1. Linux Security Fundamentals
  2. User and Group Management
  3. File System Permissions and Attributes
  4. Sudo and Privilege Escalation
  5. Process and Service Hardening
  6. Network Security Configuration
  7. System Auditing and Logging
  8. Kernel and Boot Security
  9. Software and Patch Management
  10. Malware and Rootkit Detection

Windows Access Controls

13 concepts · 41 questions
  1. Windows Access Control Model
  2. Security Identifiers (SIDs)
  3. Access Tokens
  4. Security Descriptors
  5. Discretionary Access Control Lists (DACLs)
  6. Access Control Entries (ACEs)
  7. Access Check Algorithm
  8. Inheritance of Permissions
  9. Effective Permissions
  10. Ownership and Take Ownership
  11. Privileges and User Rights
  12. Auditing and SACLs
  13. Access Control Tools

Windows as a Service

5 concepts · 34 questions
  1. Windows as a Service model
  2. Servicing channels
  3. Update types and deployment
  4. Update management tools
  5. End of servicing and support lifecycle
  1. Windows Automation Fundamentals
  2. PowerShell Scripting for Administration
  3. Windows Auditing Policies
  4. Event Log Analysis
  5. Forensic Imaging and Acquisition
  6. Windows Registry Forensics
  7. File System Forensics (NTFS)
  8. Memory Forensics on Windows
  9. Windows Artifact Analysis
  10. Automating Auditing and Forensics

Windows Security Infrastructure

12 concepts · 46 questions
  1. Windows Security Architecture
  2. Authentication Mechanisms
  3. Authorization and Access Control
  4. Security Policies and Group Policy
  5. User Account Control (UAC)
  6. Windows Firewall and Network Security
  7. Encryption and Data Protection
  8. Patch Management and Updates
  9. Security Auditing and Logging
  10. Windows Defender and Endpoint Protection
  11. Secure Configuration and Hardening
  12. Credential Protection and Management

Windows Services and Microsoft Cloud

7 concepts · 42 questions
  1. Windows Services Fundamentals
  2. Service Accounts and Permissions
  3. Securing Windows Services
  4. Microsoft Cloud Security Basics
  5. Azure Active Directory (Entra ID)
  6. Microsoft 365 Security Features
  7. Cloud Endpoint Protection

Incident Handling & Response

8 concepts · 49 questions
  1. Incident Handling Phases
  2. Incident Response Team Roles
  3. Detection and Triage
  4. Containment Strategies
  5. Eradication and Recovery
  6. Evidence Collection and Preservation
  7. Communication and Reporting
  8. Lessons Learned and Post-Incident Activities

Log Management & SIEM

8 concepts · 48 questions
  1. Log Management Fundamentals
  2. SIEM Architecture
  3. Log Collection and Aggregation
  4. Log Normalization and Parsing
  5. Correlation and Alerting
  6. Incident Detection and Response
  7. Log Retention and Compliance
  8. SIEM Tuning and Optimization

Malicious Code & Exploit Mitigation

6 concepts · 44 questions
  1. Malware Classification
  2. Malware Infection Vectors
  3. Exploit Mitigation Techniques
  4. Endpoint Protection Mechanisms
  5. Incident Response for Malware
  6. Malware Analysis Basics
  1. Vulnerability Scanning Fundamentals
  2. Scanning Tools and Techniques
  3. Scan Types and Configuration
  4. Interpreting Scan Results
  5. Penetration Testing Overview
  6. Penetration Testing Methodology
  7. Legal and Ethical Considerations
  8. Remediation and Reporting

  1. Data Loss Prevention (DLP) Fundamentals
  2. DLP Policy and Rule Creation
  3. DLP Detection Techniques
  4. DLP Response and Remediation
  5. Mobile Device Security Threats
  6. Mobile Device Management (MDM)
  7. Mobile Application Security
  8. Mobile Data Protection
  9. BYOD and COPE Strategies
  10. Integration of DLP and Mobile Security

Enforcing Windows Security Policy

7 concepts · 33 questions
  1. Windows Security Policy Overview
  2. Security Policy Components
  3. Account Policies
  4. Local Policies
  5. Security Options
  6. Group Policy Application
  7. Policy Enforcement and Verification
  1. Virtualization Fundamentals
  2. Virtualization Security Risks
  3. Virtualization Security Controls
  4. Cloud Service Models
  5. Cloud Deployment Models
  6. Cloud Security Shared Responsibility
  7. Cloud Security Best Practices
  8. AI and Machine Learning Basics
  9. AI Security Threats
  10. AI Security Defenses
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GSEC, so none is invented.