
GIAC Security Essentials
The GIAC Security Essentials (GSEC) certification validates a practitioner's hands-on capability and understanding of information security beyond simple terminology and concepts. It is designed for new InfoSec professionals, security administrators, and IT engineers who need to demonstrate fluency in crucial security paradigms and technologies. Earning GSEC proves you are qualified for hands-on roles addressing security tasks in IT systems.
1175 practice questions · Updated 2026-07-30
6Domains
26Objectives
224Concepts
1175Questions
GSEC Curriculum
Every domain, objective, and concept the GSEC exam measures.
- Access Control Models
- Access Control Mechanisms
- Password Policies
- Password Storage and Hashing
- Multi-Factor Authentication
- Password Management Tools
- Account Management
- Defense in Depth Principle
- Layered Security Controls
- Physical Security Layer
- Network Security Layer
- Host Security Layer
- Application Security Layer
- Data Security Layer
- Human Factor Layer
- Implementation of Defense in Depth
- Security Frameworks Overview
- CIS Controls Overview
- CIS Controls Implementation Groups
- CIS Controls Structure
- Applying Security Frameworks
- Defensible Network Architecture Principles
- Network Segmentation and Zoning
- Perimeter Defense
- Internal Network Hardening
- Monitoring and Logging for Defense
- Secure Remote Access
- Redundancy and High Availability
- Zero Trust Model Integration
- Network Security Devices Overview
- Firewalls
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- Unified Threat Management (UTM)
- Next-Generation Firewalls (NGFW)
- Web Application Firewalls (WAF)
- Virtual Private Network (VPN) Concentrators
- Network Access Control (NAC)
- Proxy Servers
- Load Balancers
- Security Information and Event Management (SIEM)
- Placement of Security Devices
- OSI Model Layers
- TCP/IP Model Layers
- Common Network Protocols
- Ports and Services
- IPv4 Addressing
- IPv6 Addressing
- Network Devices
- Network Topologies
- Network Models (Client-Server and Peer-to-Peer)
- Encapsulation and De-encapsulation
- MAC Addressing
- Routing Fundamentals
- Network Address Translation (NAT)
- Subnetting and CIDR
- DNS Resolution
- DHCP Operation
- Wireless Networking Basics
- Network Security Fundamentals
- Wireless Security Fundamentals
- Wireless Encryption Protocols
- Wireless Authentication Methods
- Wireless Attacks and Countermeasures
- Wireless Security Best Practices
- Symmetric Cryptography
- Asymmetric Cryptography
- Hash Functions
- Digital Signatures
- Key Management
- Cryptographic Protocols
- Cryptanalysis and Attacks
- Symmetric Cryptography
- Asymmetric Cryptography
- Hash Functions
- Digital Signatures
- Key Exchange and Management
- Public Key Infrastructure (PKI)
- Cryptographic Protocols
- Applications of Cryptography
- TLS/SSL Fundamentals
- HTTPS and Certificates
- Common Web Attacks
- Secure Web Configuration
- Web Security Headers
- Cookies and Session Management
- Web Application Firewalls (WAF)
- Container Security Fundamentals
- Container Image Security
- Container Runtime Security
- Container Orchestration Security
- macOS Security Architecture
- macOS Hardening Techniques
- macOS Malware and Threat Mitigation
- Endpoint Security Fundamentals
- Endpoint Threats and Attack Vectors
- Endpoint Protection Technologies
- Endpoint Hardening
- Endpoint Detection and Response (EDR)
- Endpoint Security Management
- Linux File System Hierarchy
- File Permissions and Ownership
- User and Group Management
- Process Management
- Package Management
- Shell Basics and Command Line
- System Logging and Monitoring
- Networking Fundamentals in Linux
- Security Hardening Basics
- Boot Process and System Initialization
- Linux Security Fundamentals
- User and Group Management
- File System Permissions and Attributes
- Sudo and Privilege Escalation
- Process and Service Hardening
- Network Security Configuration
- System Auditing and Logging
- Kernel and Boot Security
- Software and Patch Management
- Malware and Rootkit Detection
- Windows Access Control Model
- Security Identifiers (SIDs)
- Access Tokens
- Security Descriptors
- Discretionary Access Control Lists (DACLs)
- Access Control Entries (ACEs)
- Access Check Algorithm
- Inheritance of Permissions
- Effective Permissions
- Ownership and Take Ownership
- Privileges and User Rights
- Auditing and SACLs
- Access Control Tools
- Windows as a Service model
- Servicing channels
- Update types and deployment
- Update management tools
- End of servicing and support lifecycle
- Windows Automation Fundamentals
- PowerShell Scripting for Administration
- Windows Auditing Policies
- Event Log Analysis
- Forensic Imaging and Acquisition
- Windows Registry Forensics
- File System Forensics (NTFS)
- Memory Forensics on Windows
- Windows Artifact Analysis
- Automating Auditing and Forensics
- Windows Security Architecture
- Authentication Mechanisms
- Authorization and Access Control
- Security Policies and Group Policy
- User Account Control (UAC)
- Windows Firewall and Network Security
- Encryption and Data Protection
- Patch Management and Updates
- Security Auditing and Logging
- Windows Defender and Endpoint Protection
- Secure Configuration and Hardening
- Credential Protection and Management
- Windows Services Fundamentals
- Service Accounts and Permissions
- Securing Windows Services
- Microsoft Cloud Security Basics
- Azure Active Directory (Entra ID)
- Microsoft 365 Security Features
- Cloud Endpoint Protection
- Incident Handling Phases
- Incident Response Team Roles
- Detection and Triage
- Containment Strategies
- Eradication and Recovery
- Evidence Collection and Preservation
- Communication and Reporting
- Lessons Learned and Post-Incident Activities
- Log Management Fundamentals
- SIEM Architecture
- Log Collection and Aggregation
- Log Normalization and Parsing
- Correlation and Alerting
- Incident Detection and Response
- Log Retention and Compliance
- SIEM Tuning and Optimization
- Malware Classification
- Malware Infection Vectors
- Exploit Mitigation Techniques
- Endpoint Protection Mechanisms
- Incident Response for Malware
- Malware Analysis Basics
- Vulnerability Scanning Fundamentals
- Scanning Tools and Techniques
- Scan Types and Configuration
- Interpreting Scan Results
- Penetration Testing Overview
- Penetration Testing Methodology
- Legal and Ethical Considerations
- Remediation and Reporting
- Data Loss Prevention (DLP) Fundamentals
- DLP Policy and Rule Creation
- DLP Detection Techniques
- DLP Response and Remediation
- Mobile Device Security Threats
- Mobile Device Management (MDM)
- Mobile Application Security
- Mobile Data Protection
- BYOD and COPE Strategies
- Integration of DLP and Mobile Security
- Windows Security Policy Overview
- Security Policy Components
- Account Policies
- Local Policies
- Security Options
- Group Policy Application
- Policy Enforcement and Verification
- Virtualization Fundamentals
- Virtualization Security Risks
- Virtualization Security Controls
- Cloud Service Models
- Cloud Deployment Models
- Cloud Security Shared Responsibility
- Cloud Security Best Practices
- AI and Machine Learning Basics
- AI Security Threats
- AI Security Defenses
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GSEC, so none is invented.