GIAC SECURITY ESSENTIALS (GSEC) EXAM – FULL MOCK
EXAM FOR REVISION NEWEST (2026-2027 UPDATE) REAL
PAST QUESTIONS SOLVED QUESTIONS WITH ANSWERS
(FULL EXAM) (EXPERT SETTING EXAM TYPE QUESTIONS)
|ALREADY GRADED A+
1. Which security principle ensures that information is accessible to
authorized users when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Availability focuses on ensuring systems and data are accessible and usable
upon demand by authorized users.
2. What type of malware disguises itself as legitimate software to trick users
into executing it?
A. Worm
B. Virus
C. Trojan horse
D. Rootkit
A Trojan relies on social engineering and does not self-replicate like worms
or viruses.
3. Which protocol securely transfers files over an encrypted channel?
A. FTP
B. TFTP
C. SFTP
D. SNMP
SFTP uses SSH to provide encryption and secure authentication.
4. What is the primary purpose of hashing in information security?
A. Encryption of data
, B. Compression of files
C. Integrity verification
D. User authentication
Hashing ensures data has not been altered by producing a fixed-length
digest.
5. Which access control model assigns permissions based on job roles?
A. DAC
B. MAC
C. RBAC
D. Rule-based access control
Role-Based Access Control simplifies administration by grouping permissions
by role.
6. Which port number is used by HTTPS by default?
A. 21
B. 80
C. 443
D. 3389
HTTPS operates over TCP port 443 for secure web communication.
7. What does the principle of least privilege require?
A. Users receive full access by default
B. Permissions are granted permanently
C. Users receive only the access necessary to perform their tasks
D. Access is based on seniority
Least privilege reduces the attack surface by limiting unnecessary access.
8. Which device primarily filters traffic based on predefined security rules?
A. IDS
B. IPS
C. Firewall
D. Proxy server
A firewall controls network traffic by allowing or denying packets based on
rules.
, 9. What type of attack attempts to overwhelm a system with traffic to make it
unavailable?
A. Man-in-the-middle
B. Phishing
C. Denial-of-Service (DoS)
D. SQL injection
DoS attacks target availability by exhausting system resources.
10.Which encryption type uses the same key for encryption and decryption?
A. Asymmetric
B. Public key
C. Symmetric
D. Hash-based
Symmetric encryption is faster but requires secure key distribution.
11.Which authentication factor is something you are?
A. Password
B. Smart card
C. Biometric
D. PIN
Biometrics include fingerprints, iris scans, and facial recognition.
12.What is the main purpose of an Intrusion Detection System (IDS)?
A. Block malicious traffic
B. Encrypt network data
C. Detect and alert on suspicious activity
D. Replace a firewall
IDS monitors traffic and generates alerts but does not actively block attacks.
13.Which protocol is used to translate domain names into IP addresses?
A. HTTP
B. FTP
C. DNS
D. SMTP
DNS resolves human-readable domain names to IP addresses.
EXAM FOR REVISION NEWEST (2026-2027 UPDATE) REAL
PAST QUESTIONS SOLVED QUESTIONS WITH ANSWERS
(FULL EXAM) (EXPERT SETTING EXAM TYPE QUESTIONS)
|ALREADY GRADED A+
1. Which security principle ensures that information is accessible to
authorized users when needed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Availability focuses on ensuring systems and data are accessible and usable
upon demand by authorized users.
2. What type of malware disguises itself as legitimate software to trick users
into executing it?
A. Worm
B. Virus
C. Trojan horse
D. Rootkit
A Trojan relies on social engineering and does not self-replicate like worms
or viruses.
3. Which protocol securely transfers files over an encrypted channel?
A. FTP
B. TFTP
C. SFTP
D. SNMP
SFTP uses SSH to provide encryption and secure authentication.
4. What is the primary purpose of hashing in information security?
A. Encryption of data
, B. Compression of files
C. Integrity verification
D. User authentication
Hashing ensures data has not been altered by producing a fixed-length
digest.
5. Which access control model assigns permissions based on job roles?
A. DAC
B. MAC
C. RBAC
D. Rule-based access control
Role-Based Access Control simplifies administration by grouping permissions
by role.
6. Which port number is used by HTTPS by default?
A. 21
B. 80
C. 443
D. 3389
HTTPS operates over TCP port 443 for secure web communication.
7. What does the principle of least privilege require?
A. Users receive full access by default
B. Permissions are granted permanently
C. Users receive only the access necessary to perform their tasks
D. Access is based on seniority
Least privilege reduces the attack surface by limiting unnecessary access.
8. Which device primarily filters traffic based on predefined security rules?
A. IDS
B. IPS
C. Firewall
D. Proxy server
A firewall controls network traffic by allowing or denying packets based on
rules.
, 9. What type of attack attempts to overwhelm a system with traffic to make it
unavailable?
A. Man-in-the-middle
B. Phishing
C. Denial-of-Service (DoS)
D. SQL injection
DoS attacks target availability by exhausting system resources.
10.Which encryption type uses the same key for encryption and decryption?
A. Asymmetric
B. Public key
C. Symmetric
D. Hash-based
Symmetric encryption is faster but requires secure key distribution.
11.Which authentication factor is something you are?
A. Password
B. Smart card
C. Biometric
D. PIN
Biometrics include fingerprints, iris scans, and facial recognition.
12.What is the main purpose of an Intrusion Detection System (IDS)?
A. Block malicious traffic
B. Encrypt network data
C. Detect and alert on suspicious activity
D. Replace a firewall
IDS monitors traffic and generates alerts but does not actively block attacks.
13.Which protocol is used to translate domain names into IP addresses?
A. HTTP
B. FTP
C. DNS
D. SMTP
DNS resolves human-readable domain names to IP addresses.