Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 6Objective 1

Data Loss Prevention and Mobile Device Security GSEC Practice Questions (Page 7)

Part of the Data Protection and Emerging Technologies domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
10concepts

Questions 31–35

  1. 31application · medium

    A company allows employees to install third-party apps on their corporate-owned smartphones. A recent incident involved a malicious app that accessed contacts and sent them to an external server. To prevent this, the security team wants to enforce a policy that limits app permissions. Which MDM policy should be implemented?

    Select an answer first
  2. 32application · medium

    A company's mobile app development team is creating a new corporate app that will handle sensitive financial data. The security team wants to ensure the app follows best practices for data protection on mobile devices. Which control should be implemented within the app?

    Select an answer first
  3. 33expert · hard

    A company is implementing a COPE program and wants to ensure that corporate data on the devices is protected even if the device is lost or stolen. The security team is considering using a secure container for corporate apps and data. However, some employees need to use the native email app to access corporate email, which is not supported in the container. What should the security team do?

    Select an answer first
  4. 34expert · hard

    A DLP administrator is creating a policy to prevent the exfiltration of source code via email. The source code is stored in a central repository, and developers often copy code snippets into emails. The administrator wants to detect full source files but allow small code snippets for collaboration. Which detection technique should be used?

    Select an answer first
  5. 35expert · hard

    A company is implementing MDM for a mix of corporate-owned and BYOD devices. The security team wants to enforce a policy that requires a PIN and encryption on all devices. However, some BYOD users have older devices that do not support the required encryption standard. What should the MDM administrator do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.