Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 4Objective 1

Container and MacOS Security GSEC Practice Questions (Page 2)

Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)

43questions here
9free pages
7concepts

Questions 6–10

  1. 6expert · hard

    A container runs as root inside its user namespace but is mapped to a non-root user on the host. The security team wants to prevent the container from gaining additional capabilities beyond those required. Which configuration is most effective?

    Select an answer first
  2. 7application · medium

    A Kubernetes cluster hosts multiple applications from different teams. The security team wants to ensure that only the payments team can read the database credentials stored as a Secret. What is the most appropriate control?

    Select an answer first
  3. 8foundation · easy

    What is the primary security purpose of setting resource limits (e.g., memory and CPU) on a container?

    Select an answer first
  4. 9expert · hard

    A security team is designing a container platform. They need strong isolation between containers but also want to minimize overhead and maintain high density. Which approach best balances these requirements?

    Select an answer first
  5. 10foundation · easy

    Which macOS security feature protects system files and processes from being modified even by the root user?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.