
GIAC Security Essentials
Domain 1Objective 2
Defense in Depth GSEC Practice Questions (Page 5)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 21–25
- 21
Which network security device is designed to inspect traffic and block malicious packets in real time?
Select an answer first - 22
A company has deployed a next-generation firewall, an intrusion prevention system, and endpoint protection. During a recent incident, an employee clicked a phishing link and entered credentials on a fake login page. Which additional control would most directly address the human factor layer to prevent a recurrence?
Select an answer first - 23
A regional bank is deploying a new customer-facing web application that will handle sensitive financial data. The security architect wants to ensure that even if an attacker compromises the web server, the underlying database contents remain protected. Which combination of controls best achieves this objective?
Select an answer first - 24
A company's endpoints are frequently infected with malware that exploits unpatched software. The security team has already deployed antivirus and a firewall. Which additional host-level control would be most effective in reducing the number of infections?
Select an answer first - 25
What is the primary purpose of patch management on endpoints?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.