
GIAC Security Essentials
Domain 1Objective 2
Defense in Depth GSEC Practice Questions (Page 10)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 46–50
- 46
Which statement best describes the defense-in-depth security principle?
Select an answer first - 47
Which of the following is an example of a physical security control?
Select an answer first - 48
A hospital network stores patient records in a database that must be accessible to clinicians on the internal network. The security team wants to protect the database from both external attackers and internal threats, while ensuring that clinicians can still reach it. Which combination of controls best implements defense in depth for this database?
Select an answer first - 49
A security analyst is reviewing the defense-in-depth posture of a company. The company has a firewall, an IDS, antivirus on all endpoints, and a patch management program. During a recent incident, an attacker was able to move laterally from a compromised workstation to a file server. Which control is most likely to have prevented this lateral movement?
Select an answer first - 50
A company has a high rate of employees sharing passwords and writing them down. The security team wants to reduce the risk of credential theft and unauthorized access. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.