
GIAC Security Essentials
Domain 3Objective 2
Cryptography Application GSEC Practice Questions (Page 3)
Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 11–15
- 11
What is the primary purpose of the Diffie-Hellman key exchange protocol?
Select an answer first - 12
A small business wants to encrypt files stored on a shared network drive. Employees need to access the files from multiple devices, and the business wants to minimize the complexity of key management. Which approach is most appropriate?
Select an answer first - 13
A developer is designing a system where users submit documents and the system must prove that a specific user submitted a specific document at a later time. The system does not need to keep the document secret. Which cryptographic approach should the developer use?
Select an answer first - 14
A company wants to deploy a private PKI for internal services. They need to ensure that clients can automatically trust certificates issued by the internal CA. What is the most efficient way to achieve this?
Select an answer first - 15
A security engineer is designing a system to store user passwords. The system must resist offline brute-force attacks even if the password database is leaked. The engineer also wants to avoid the overhead of a key management system. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.