
GIAC Security Essentials
Domain 1Objective 2
Defense in Depth GSEC Practice Questions (Page 4)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 16–20
- 16
A company has a strong technical security posture, but a recent social engineering attack succeeded because an employee shared their password over the phone. The security team wants to implement a control that would have prevented this specific incident. Which control is the most effective?
Select an answer first - 17
A development team is deploying a web application that accepts user-uploaded files. The security team wants to prevent malicious files from being executed on the server. Which combination of application and host controls is most appropriate?
Select an answer first - 18
After a malware infection is discovered on a workstation, the IT team restores the system from a clean backup. Which type of security control is this?
Select an answer first - 19
When designing a defense-in-depth architecture for a web application, which set of controls would be most appropriate?
Select an answer first - 20
A company has experienced several incidents where employees plugged unauthorized USB drives into their workstations, leading to malware infections. The security team wants to reduce this risk without completely banning USB devices, because some employees need them for legitimate work. Which approach best balances security and usability?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.