
GIAC Security Essentials
Domain 5Objective 4
Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 10)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 46–48
- 46
A security team needs to identify misconfigurations and missing patches on all servers in a data center. The team wants to minimize network impact and avoid disrupting production services. Which scanning approach should the team use?
Select an answer first - 47
A company wants to assess the security of its internal network by simulating an attack from an external perspective. The company has hired a penetration testing firm. Before the test begins, what is the most important legal document or agreement that must be in place?
Select an answer first - 48
What should a vulnerability scan report include to help stakeholders prioritize remediation?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GSEC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.