Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 4

Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 5)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)

48questions here
10free pages
8concepts

Questions 21–25

  1. 21expert · hard

    A penetration test is being planned for a healthcare organization that must comply with HIPAA. The test will involve scanning systems that contain protected health information (PHI). What is the most critical consideration?

    Select an answer first
  2. 22application · medium

    A security manager wants to identify as many potential vulnerabilities as possible in a short time, without actively exploiting them. The goal is to get a baseline of the organization's security posture. Which activity should the manager choose?

    Select an answer first
  3. 23expert · hard

    A security team is planning a vulnerability scan of a large enterprise network that includes both internal servers and public-facing web applications. The team wants to minimize the risk of disrupting production services while still obtaining comprehensive coverage. The scan must be completed within a maintenance window of 4 hours. Which approach best balances these constraints?

    Select an answer first
  4. 24application · medium

    A company is about to launch a new customer-facing web application. The security team wants to identify common web vulnerabilities before launch. The application is hosted in a cloud environment and uses a mix of third-party and custom components. What is the most appropriate scan type?

    Select an answer first
  5. 25application · medium

    A company wants to test its incident response capabilities by simulating a realistic attack. The test should not be limited to a specific system or vulnerability, and the attackers should have no prior knowledge of the environment. What type of test should the company conduct?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.