
GIAC Security Essentials
Domain 6Objective 2
Enforcing Windows Security Policy GSEC Practice Questions (Page 4)
Part of the Data Protection and Emerging Technologies domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
Questions 16–20
- 16
A domain administrator needs to enforce a 10-attempt lockout policy for all users in the finance department, but the rest of the company should retain the default 5-attempt lockout. The finance users are in an OU named 'Finance'. What is the correct approach?
Select an answer first - 17
A security administrator needs to ensure that all failed logon attempts are recorded in the Security log on a Windows server. Which audit policy setting should be enabled?
Select an answer first - 18
Which Account Policy setting enforces a minimum number of characters for a user's password?
Select an answer first - 19
An organization has a GPO that sets 'Account lockout threshold' to 3 and 'Account lockout duration' to 15 minutes. The GPO is linked to the domain root. A user reports that their account is locked out after a single failed password attempt. The administrator verifies the GPO is applied. What is the most likely cause?
Select an answer first - 20
A company wants to prevent users from seeing the last signed-in username on the Windows logon screen to reduce the risk of targeted attacks. Which Security Options setting should be configured?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.