
GIAC Security Essentials
Domain 1Objective 2
Defense in Depth GSEC Practice Questions (Page 6)
Part of the Foundations of Security domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~10–18 in this domain), expect 3–6 from this objective — we provide 55 practice questions to prepare you well beyond it. (estimate)
55questions here
11free pages
9concepts
Questions 26–30
- 26
Which application security practice is most effective at preventing SQL injection attacks?
Select an answer first - 27
A company runs a public-facing web application that handles customer orders. The application has been targeted by SQL injection and cross-site scripting (XSS) attacks. The security team wants to add layers of protection without rewriting the application immediately. Which approach is most effective?
Select an answer first - 28
A company is designing a new data center. The security team wants to protect against both unauthorized physical access and theft of servers. Which combination of physical controls is most effective?
Select an answer first - 29
A company has implemented strong technical controls, but employees still fall for phishing emails and share passwords. The security team wants to improve the human factor layer. Which approach is most effective?
Select an answer first - 30
A small e-commerce company is designing a new architecture for its online store. The budget is limited, and the team must choose a set of controls that provides the best defense in depth without over-engineering. The store will be hosted on a single server with a public IP. Which set of controls is the most balanced and effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.