Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 4

Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 3)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 11–15

  1. 11application · medium

    During a penetration test, the tester has completed the reconnaissance phase and identified a vulnerable web application. The tester now wants to confirm the vulnerability can be exploited to gain access to the server. What should the tester do next?

    Select an answer first
  2. 12expert · hard

    A security team is planning a vulnerability scan of a large enterprise network. The scan must be completed within a maintenance window of four hours. The network has multiple segments, and some segments contain critical systems that cannot be disrupted. What is the most effective approach?

    Select an answer first
  3. 13application · medium

    After a penetration test, the tester has identified a critical vulnerability in a custom web application. The development team is unfamiliar with the vulnerability and needs clear guidance on how to fix it. What should the tester provide in the report?

    Select an answer first
  4. 14application · medium

    A security team needs to identify unpatched software on a fleet of Windows servers. The team has administrative credentials and wants to minimize network traffic. Which approach is most effective?

    Select an answer first
  5. 15application · medium

    A penetration tester is performing a test on a client's network. The tester has completed the exploitation phase and gained access to a server. The tester now wants to understand the extent of the compromise and identify other systems that can be accessed. What phase of the penetration test is the tester in?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.