
GIAC Security Essentials
Domain 5Objective 4
Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 4)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 16–20
- 16
A security team needs to scan a web application for common vulnerabilities such as SQL injection and cross-site scripting. The team wants to automate the scanning process and integrate it into their CI/CD pipeline. Which type of scan should the team use?
Select an answer first - 17
A security analyst is using a vulnerability scanner to assess a mixed environment of Windows and Linux servers. The analyst wants to reduce false positives and obtain more accurate information about missing patches. What should the analyst do?
Select an answer first - 18
A security analyst needs to identify open ports and services running on a set of servers to assess their attack surface. The analyst wants a quick, unauthenticated overview of the network. Which tool is most appropriate for this task?
Select an answer first - 19
When recommending remediation for a vulnerability, what is the most important factor to consider?
Select an answer first - 20
What is the final phase of a standard penetration testing methodology?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.