Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 4

Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 1)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 1–5

  1. 1application · medium

    A security analyst at a mid-sized company runs a quarterly vulnerability scan against all internal hosts. The report shows a critical-severity remote code execution vulnerability on a legacy application server that is not exposed to the internet, and a high-severity missing security patch on an internet-facing web server. The analyst has limited time and must decide which to remediate first. What should the analyst do?

    Select an answer first
  2. 2foundation · easy

    Which tool is commonly used for network vulnerability scanning and provides a web-based dashboard for managing scan results?

    Select an answer first
  3. 3application · medium

    After a penetration test, the tester has documented a critical remote code execution vulnerability in an internal application. The application owner argues that the risk is low because the application is only accessible from the internal network. What should the tester include in the report to address this?

    Select an answer first
  4. 4expert · hard

    A security manager is deciding between a vulnerability scan and a penetration test for a new application. The goal is to determine if the application can be compromised by an external attacker. The budget is limited, and the application is not yet in production. What is the most appropriate choice?

    Select an answer first
  5. 5application · medium

    A penetration tester is hired to assess the security of a client's external web application. The client provides the tester with valid user credentials for a standard user account and asks the tester to attempt to escalate privileges. The tester has no prior knowledge of the internal network or source code. What type of penetration test is this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.