
GIAC Security Essentials
Domain 1Objective 1
Access Control & Password Management GSEC Practice Questions (Page 1)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 1–5
- 1
An employee is transferred from the sales department to the marketing department. The IT admin needs to update the employee's access rights. What is the best practice?
Select an answer first - 2
Which access control model is most appropriate for an organization that must enforce a security policy where access decisions are based on the sensitivity labels of data and the clearance levels of users, regardless of the data owner's preferences?
Select an answer first - 3
Which of the following is an example of the 'something you have' authentication factor?
Select an answer first - 4
In which access control model does the owner of a resource have the discretion to grant or revoke access to that resource for other users?
Select an answer first - 5
A company wants to implement MFA for remote workers. They are considering SMS codes, a mobile authenticator app, and hardware security keys. Which factor should they choose to balance security and usability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.