Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 3Objective 3

Web Communication Security GSEC Practice Questions (Page 8)

Part of the Cryptography and Communications domain, which makes up ~12% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 46 practice questions to prepare you well beyond it. (estimate)

46questions here
10free pages
7concepts

Questions 36–40

  1. 36application · medium

    A company is deploying a public web application and wants to protect it from common web attacks such as SQL injection and cross-site scripting. The application is hosted on a cloud platform and uses a load balancer. The security team wants a solution that can automatically update its rules as new vulnerabilities are discovered. Which approach best meets these requirements?

    Select an answer first
  2. 37application · medium

    A system administrator is configuring a new web server for a public-facing site. The site will handle sensitive customer data. The administrator wants to enforce that clients always use HTTPS and cannot fall back to HTTP. Which configuration should be applied?

    Select an answer first
  3. 38expert · hard

    A security analyst is troubleshooting a TLS handshake failure. The client and server both support TLS 1.2, but the handshake fails. The server's certificate is valid and trusted. The analyst checks the server logs and finds that the client is offering a cipher suite that the server does not support. What is the most likely cause of the failure?

    Select an answer first
  4. 39foundation · easy

    Which attack involves an attacker intercepting and potentially altering the communication between a client and server without either party knowing?

    Select an answer first
  5. 40application · medium

    A user on a public Wi-Fi network connects to a website that supports both HTTP and HTTPS. An attacker on the same network intercepts the initial HTTP request and redirects the user to a look-alike site that uses a self-signed certificate. The user's browser displays a certificate warning, but the user clicks through. What is the primary security control that would have prevented this attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.