
GIAC Security Essentials
Domain 5Objective 4
Vulnerability Scanning and Penetration Testing GSEC Practice Questions (Page 6)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 26–30
- 26
A vulnerability scan report shows a high-severity vulnerability on a server that is scheduled for decommissioning in two weeks. The same report shows a medium-severity vulnerability on a server that hosts a critical business application. The security team has limited resources. What should the team do?
Select an answer first - 27
What type of output does a typical vulnerability scanner produce?
Select an answer first - 28
What is the purpose of defining the scope in a penetration testing engagement?
Select an answer first - 29
What does the 'intensity' setting on a vulnerability scanner control?
Select an answer first - 30
A vulnerability scan of a web application reports a medium-severity cross-site scripting (XSS) vulnerability in a search function. The application is used internally by employees, and the search function is not accessible to external users. The security team has a limited budget. What is the most appropriate action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.