ESTUDY
SANS GICSP UPDATE LATEST EXAM | MOST TESTED
QUESTIONS AND VERIFIED ANSWERS GRADED A+
WITH RATIONALES
1. Which access control model focuses on the flow of information and non-interference?
a) Bell-LaPadula
b) Biba
c) Information Flow and Non-Interference
d) Clark-Wilson
Rationale: Information Flow and Non-Interference models focus on controlling how information
flows within a system and ensuring that actions at one level do not interfere with another.
2. Which model is used to enforce confidentiality in stored information?
a) Bell-LaPadula
b) Biba
c) Clark-Wilson
d) Take-Grant
Rationale: The Bell-LaPadula model is designed to enforce confidentiality by restricting access
based on security levels.
3. What is the primary focus of the Biba Integrity Model?
a) Confidentiality
b) Integrity
c) Availability
d) Non-repudiation
Rationale: The Biba Integrity Model ensures that data integrity is maintained by preventing
unauthorized modification of data.
4. Which access control model allows the owner of a file to determine access permissions?
a) Mandatory Access Control (MAC)
b) Discretionary Access Control (DAC)
c) Role-Based Access Control (RBAC)
d) Rule-Based Access Control
Rationale: DAC allows the owner of a file or resource to decide who can access it and what
permissions they have.
5. What is the primary characteristic of Mandatory Access Control (MAC)?
a) The owner determines access permissions
b) Permissions are managed centrally by an administrator
c) Access is based on group membership
,ESTUDY
d) Access is determined by user roles
Rationale: MAC is centrally managed by an administrator and is often used in systems handling
highly sensitive data.
6. Which of the following is an example of Mandatory Access Control (MAC)?
a) Role-Based Access Control
b) Lattice Model
c) Discretionary Access Control
d) Rule-Based Access Control
Rationale: The Lattice Model is an example of MAC, which uses a mathematical structure to
define access levels.
7. What is the main purpose of Role-Based Access Control (RBAC)?
a) To allow owners to set permissions
b) To base access decisions on group membership and organizational roles
c) To enforce confidentiality through security levels
d) To ensure data integrity
Rationale: RBAC assigns permissions based on roles within an organization, simplifying access
management.
8. Which protocol supports authentication and directory functions in a network?
a) HTTP
b) LDAP (Lightweight Directory Access Protocol)
c) FTP
d) SNMP
Rationale: LDAP is used for accessing and managing directory information services, such as user
authentication.
9. What is the purpose of a user account?
a) To manage system resources
b) To allow a user to authenticate and access system services
c) To provide temporary access to guests
d) To run system services
Rationale: A user account enables authentication and authorization for accessing system
services.
10. What is a service account typically used for?
a) To allow users to log in temporarily
b) To run system services or scheduled tasks
c) To provide administrative access
d) To manage guest access
Rationale: Service accounts are used to run system services or scheduled tasks without using a
personal user account.
,ESTUDY
11. What is a default account?
a) An account created by the system administrator
b) A predefined account in a system for initial access
c) An account used for guest access
d) An account used for running services
Rationale: Default accounts are predefined in systems to allow initial access during setup.
12. What is the primary purpose of a guest account?
a) To provide full access to system resources
b) To allow temporary access without granting personal file access
c) To run system services
d) To manage administrative tasks
Rationale: Guest accounts provide limited access for temporary users without allowing access to
personal files.
13. What does account expiration refer to?
a) The time a user logs out of the system
b) A time limit applied to the life of an account
c) The time a service account is deactivated
d) The time a guest account is created
Rationale: Account expiration sets a time limit for how long an account can be used.
14. What is an Access Control List (ACL)?
a) A list of system services
b) A list of subjects authorized to access an object
c) A list of user roles
d) A list of default accounts
Rationale: An ACL specifies which subjects (users, groups, etc.) are authorized to access an
object and their permissions.
15. What is the purpose of access reconciliation?
a) To create new user accounts
b) To ensure accounts are consistent and accurate
c) To delete expired accounts
d) To manage service accounts
Rationale: Access reconciliation ensures that account records are consistent and accurate across
systems.
16. What is configuration control?
a) The process of creating new system configurations
b) The process of controlling modifications to hardware, software, and documentation
c) The process of managing user accounts
d) The process of setting up guest accounts
, ESTUDY
Rationale: Configuration control ensures that modifications to systems are properly managed
and documented.
17. What is a baseline configuration?
a) A temporary system setup
b) A set of specifications formally reviewed and agreed upon for a system
c) A list of default accounts
d) A configuration used for testing
Rationale: A baseline configuration is a standardized set of specifications used as a reference for
system builds and changes.
18. What is the purpose of configuration auditing?
a) To create new configurations
b) To verify that changes were recorded correctly and configurations are updated
c) To delete outdated configurations
d) To manage user accounts
Rationale: Configuration auditing ensures that changes are properly documented and
configurations are accurate.
19. What is WSUS (Windows Server Update Services) used for?
a) To manage user accounts
b) To provide automatic updates for internal systems
c) To configure baseline settings
d) To audit system configurations
Rationale: WSUS is used to manage and distribute updates within an organization.
20. What is a Man-in-the-Middle (MITM) attack?
a) An attack that floods a network with traffic
b) An attack where an attacker intercepts and modifies messages between two parties
c) An attack that exploits social engineering
d) An attack that spoofs IP addresses
Rationale: In a MITM attack, the attacker intercepts and potentially alters communication
between two parties.
21. What is spoofing in the context of network attacks?
a) Flooding a network with traffic
b) Forging packet information to impersonate a trusted host
c) Exploiting social engineering techniques
d) Intercepting communication between two parties
Rationale: Spoofing involves forging packet information, such as IP addresses, to impersonate a
trusted entity.
22. What is social engineering?
a) A technical attack on network protocols
SANS GICSP UPDATE LATEST EXAM | MOST TESTED
QUESTIONS AND VERIFIED ANSWERS GRADED A+
WITH RATIONALES
1. Which access control model focuses on the flow of information and non-interference?
a) Bell-LaPadula
b) Biba
c) Information Flow and Non-Interference
d) Clark-Wilson
Rationale: Information Flow and Non-Interference models focus on controlling how information
flows within a system and ensuring that actions at one level do not interfere with another.
2. Which model is used to enforce confidentiality in stored information?
a) Bell-LaPadula
b) Biba
c) Clark-Wilson
d) Take-Grant
Rationale: The Bell-LaPadula model is designed to enforce confidentiality by restricting access
based on security levels.
3. What is the primary focus of the Biba Integrity Model?
a) Confidentiality
b) Integrity
c) Availability
d) Non-repudiation
Rationale: The Biba Integrity Model ensures that data integrity is maintained by preventing
unauthorized modification of data.
4. Which access control model allows the owner of a file to determine access permissions?
a) Mandatory Access Control (MAC)
b) Discretionary Access Control (DAC)
c) Role-Based Access Control (RBAC)
d) Rule-Based Access Control
Rationale: DAC allows the owner of a file or resource to decide who can access it and what
permissions they have.
5. What is the primary characteristic of Mandatory Access Control (MAC)?
a) The owner determines access permissions
b) Permissions are managed centrally by an administrator
c) Access is based on group membership
,ESTUDY
d) Access is determined by user roles
Rationale: MAC is centrally managed by an administrator and is often used in systems handling
highly sensitive data.
6. Which of the following is an example of Mandatory Access Control (MAC)?
a) Role-Based Access Control
b) Lattice Model
c) Discretionary Access Control
d) Rule-Based Access Control
Rationale: The Lattice Model is an example of MAC, which uses a mathematical structure to
define access levels.
7. What is the main purpose of Role-Based Access Control (RBAC)?
a) To allow owners to set permissions
b) To base access decisions on group membership and organizational roles
c) To enforce confidentiality through security levels
d) To ensure data integrity
Rationale: RBAC assigns permissions based on roles within an organization, simplifying access
management.
8. Which protocol supports authentication and directory functions in a network?
a) HTTP
b) LDAP (Lightweight Directory Access Protocol)
c) FTP
d) SNMP
Rationale: LDAP is used for accessing and managing directory information services, such as user
authentication.
9. What is the purpose of a user account?
a) To manage system resources
b) To allow a user to authenticate and access system services
c) To provide temporary access to guests
d) To run system services
Rationale: A user account enables authentication and authorization for accessing system
services.
10. What is a service account typically used for?
a) To allow users to log in temporarily
b) To run system services or scheduled tasks
c) To provide administrative access
d) To manage guest access
Rationale: Service accounts are used to run system services or scheduled tasks without using a
personal user account.
,ESTUDY
11. What is a default account?
a) An account created by the system administrator
b) A predefined account in a system for initial access
c) An account used for guest access
d) An account used for running services
Rationale: Default accounts are predefined in systems to allow initial access during setup.
12. What is the primary purpose of a guest account?
a) To provide full access to system resources
b) To allow temporary access without granting personal file access
c) To run system services
d) To manage administrative tasks
Rationale: Guest accounts provide limited access for temporary users without allowing access to
personal files.
13. What does account expiration refer to?
a) The time a user logs out of the system
b) A time limit applied to the life of an account
c) The time a service account is deactivated
d) The time a guest account is created
Rationale: Account expiration sets a time limit for how long an account can be used.
14. What is an Access Control List (ACL)?
a) A list of system services
b) A list of subjects authorized to access an object
c) A list of user roles
d) A list of default accounts
Rationale: An ACL specifies which subjects (users, groups, etc.) are authorized to access an
object and their permissions.
15. What is the purpose of access reconciliation?
a) To create new user accounts
b) To ensure accounts are consistent and accurate
c) To delete expired accounts
d) To manage service accounts
Rationale: Access reconciliation ensures that account records are consistent and accurate across
systems.
16. What is configuration control?
a) The process of creating new system configurations
b) The process of controlling modifications to hardware, software, and documentation
c) The process of managing user accounts
d) The process of setting up guest accounts
, ESTUDY
Rationale: Configuration control ensures that modifications to systems are properly managed
and documented.
17. What is a baseline configuration?
a) A temporary system setup
b) A set of specifications formally reviewed and agreed upon for a system
c) A list of default accounts
d) A configuration used for testing
Rationale: A baseline configuration is a standardized set of specifications used as a reference for
system builds and changes.
18. What is the purpose of configuration auditing?
a) To create new configurations
b) To verify that changes were recorded correctly and configurations are updated
c) To delete outdated configurations
d) To manage user accounts
Rationale: Configuration auditing ensures that changes are properly documented and
configurations are accurate.
19. What is WSUS (Windows Server Update Services) used for?
a) To manage user accounts
b) To provide automatic updates for internal systems
c) To configure baseline settings
d) To audit system configurations
Rationale: WSUS is used to manage and distribute updates within an organization.
20. What is a Man-in-the-Middle (MITM) attack?
a) An attack that floods a network with traffic
b) An attack where an attacker intercepts and modifies messages between two parties
c) An attack that exploits social engineering
d) An attack that spoofs IP addresses
Rationale: In a MITM attack, the attacker intercepts and potentially alters communication
between two parties.
21. What is spoofing in the context of network attacks?
a) Flooding a network with traffic
b) Forging packet information to impersonate a trusted host
c) Exploiting social engineering techniques
d) Intercepting communication between two parties
Rationale: Spoofing involves forging packet information, such as IP addresses, to impersonate a
trusted entity.
22. What is social engineering?
a) A technical attack on network protocols