Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 3Objective 3

Web Communication Security GSEC Practice Questions (Page 3)

Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of the X-Frame-Options header?

    Select an answer first
  2. 12application · medium

    A small e-commerce company recently deployed a new web application. Users report that when they visit the site, the browser shows a warning that the connection is not private, and the URL bar does not display a padlock. The site is reachable at https://www.example.com. The administrator confirms the web server is listening on port 443 and the certificate is installed. Which action would most directly resolve the user-facing warning?

    Select an answer first
  3. 13foundation · easy

    Which practice helps prevent session hijacking?

    Select an answer first
  4. 14expert · hard

    A security analyst is investigating a potential downgrade attack. The web server supports TLS 1.2 and TLS 1.3, but the analyst notices that some clients are connecting with TLS 1.0. The server logs show that these connections are coming from a legacy application that does not support newer TLS versions. The company must maintain compatibility with this legacy application but also wants to prevent downgrade attacks. Which approach best balances security and compatibility?

    Select an answer first
  5. 15application · medium

    A web application uses cookies to maintain user sessions. A penetration test reveals that an attacker can set a session cookie for a victim's browser by exploiting a subdomain that shares the parent domain. The attacker then waits for the victim to log in and uses the attacker's known session token. What type of attack is this, and what is the most effective mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.