
GIAC Security Essentials
Domain 4Objective 1
Container and MacOS Security GSEC Practice Questions (Page 6)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
7concepts
Questions 26–30
- 26
A macOS user has a legitimate application that is being flagged by XProtect as malware. The application is critical for the user's work and is from a trusted vendor. What is the most appropriate action?
Select an answer first - 27
A security team wants to ensure that only images from a trusted internal registry can be deployed in their Kubernetes cluster. Which control should they implement?
Select an answer first - 28
A Kubernetes cluster runs a multi-tenant workload. The security team must prevent a compromised pod from communicating with pods in other namespaces, while still allowing it to reach the Kubernetes API server for health checks. Which set of controls best achieves this?
Select an answer first - 29
What is a common mitigation strategy for a macOS device infected with malware?
Select an answer first - 30
A security analyst is reviewing a container image used in production. The image was built from a base image that is several months old and includes a known critical vulnerability. The team wants to continue using the image but reduce risk. What is the most effective immediate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.