
GIAC Security Essentials
Domain 3Objective 2
Cryptography Application GSEC Practice Questions (Page 8)
Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
Which technology is commonly used to secure email messages by encrypting and digitally signing them?
Select an answer first - 37
An organization operates its own internal certificate authority (CA) to issue certificates for employee email signing. A senior manager's private key is suspected to have been compromised. What is the most appropriate immediate action to protect others who rely on certificates issued to that manager?
Select an answer first - 38
An organization's web server certificate is about to expire. The administrator plans to replace it with a new certificate from the same public CA. What must the administrator do to ensure clients will trust the new certificate without manual intervention?
Select an answer first - 39
A company must store customer passwords in a database. They want to protect the passwords even if the database is compromised. Which approach is the most secure and practical?
Select an answer first - 40
A software vendor distributes a signed update file. The vendor's public key is widely known. To verify the authenticity and integrity of the update, what should the recipient do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.