
GIAC Security Essentials
Domain 1Objective 2
Defense in Depth GSEC Practice Questions (Page 1)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 1–5
- 1
Why is security awareness training considered a critical layer in defense-in-depth?
Select an answer first - 2
A company runs a legacy web application that cannot be easily patched. The application is critical to business operations. The security team wants to protect it from known vulnerabilities while it remains in service. Which approach is most appropriate?
Select an answer first - 3
A financial services firm must protect customer data in transit and at rest. They also need to ensure that only authorized employees can access the data. Which combination of data security controls is most appropriate?
Select an answer first - 4
A data center operator wants to protect against an attacker who gains physical access to the building. Which combination of physical and logical controls would be most effective?
Select an answer first - 5
What is the primary function of a web application firewall (WAF)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.