GIAC SECURITY ESSENTIALS (GSEC) –QUESTIONS AND CORRECT ANSWERS (VERIFIED
ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.
*Core Domains*
*• Access Control Systems and Methodology*
*• Cryptographic Concepts and Applications*
*• Network Protocols and Packet Analysis*
*• Windows and Linux Host Security*
*• Incident Response and Vulnerability Management*
*• Cloud Security and Virtualization*
*• Defense-in-Depth and Security Architecture*
*• Governance, Risk, Compliance, and Ethics*
*Introduction*
*The GIAC Security Essentials assessment validates a candidate's mastery of information security beyon
SECTION ONE: QUESTIONS 1–100
Question 1
An administrator discovers that a database server containing sensitive customer records is accessible
directly from the public internet via port 1433. Which security architecture principle has been violated?
A. Defense-in-depth
B. Least privilege
,C. Separation of duties
D. Fail-secure
🟢 Correct answer: A
🔴 RATIONALE: Defense-in-depth involves layering multiple security controls so that the failure of a
single control (such as a firewall rule or network segment) does not expose critical assets. Exposing a
database directly to the internet shows a lack of layered boundary defense.
Question 2
A network security analyst runs a packet capture and observes an HTTP flood targeting a web application.
The traffic originates from hundreds of distinct IP addresses distributed globally. Which type of attack is
occurring?
A. Man-in-the-middle attack
B. Distributed Denial of Service
C. Brute-force attack
D. Address Resolution Protocol spoofing
🟢 Correct answer: B
🔴 RATIONALE: A Distributed Denial of Service (DDoS) attack coordinates multiple compromised
systems across the globe to flood a target destination with traffic, overwhelming its capacity and
exhausting resources.
Question 3
An organization is designing a cryptographic standard for securing internal web traffic. They need an
encryption algorithm that provides high speed and efficiency for large volumes of data. Which of the
following should they select?
A. RSA
B. ECC
C. AES
D. Diffie-Hellman
🟢 Correct answer: C
,🔴 RATIONALE: The Advanced Encryption Standard (AES) is a symmetric encryption algorithm, making
it vastly faster and more efficient at encrypting large volumes of data compared to asymmetric algorithms
like RSA, ECC, or Diffie-Hellman.
Question 4
A company wants to prevent employees from installing unauthorized software on corporate laptops.
Which of the following technical solutions provides the most robust control?
A. Implementing an acceptable use policy
B. Running weekly vulnerability scans
C. Deploying application blocklisting
D. Implementing application allowlisting
🟢 Correct answer: D
🔴 RATIONALE: Application allowlisting is a proactive endpoint security practice that permits only explicit,
approved binaries to execute on a system, blocking all unauthorized software by default. Blocklisting is
reactive and easily bypassed by renaming or modifying files.
Question 5
During an audit, a security team finds that system administrators share a single "root" account to perform
emergency updates on Linux servers. Which fundamental security objective is compromised?
A. Confidentiality
B. Integrity
C. Accountability
D. Availability
🟢 Correct answer: C
🔴 RATIONALE: Accountability requires that every action on a system can be definitively traced back to a
specific individual. Sharing a privileged account eliminates individual attribution, destroying accountability.
Question 6
A standard Ethernet frame header contains which type of addressing information to guide local network
delivery?
, A. IP addresses
B. MAC addresses
C. TCP port numbers
D. Logical block addresses
🟢 Correct answer: B
🔴 RATIONALE: Media Access Control (MAC) addresses operate at Data Link Layer (Layer 2) of the OSI
model and are contained in the Ethernet frame header to direct traffic between nodes on the same local
network segment.
Question 7
A company needs to comply with the Payment Card Industry Data Security Standard (PCI DSS). During a
review, they notice primary account numbers (PAN) are stored in plain text files. What action is required to
meet compliance?
A. Compress the plain text files using a zip utility
B. Render the PAN unreadable using strong cryptography
C. Move the plain text files to a hidden network share
D. Instruct employees to delete old card numbers manually
🟢 Correct answer: B
🔴 RATIONALE: PCI DSS strictly mandates that the Primary Account Number (PAN) must be rendered
unreadable anywhere it is stored, which is typically achieved through strong encryption, hashing, or
tokenization.
Question 8
An employee receives an urgent email claiming to be from the company CEO, demanding an immediate
wire transfer to a new vendor. The email address looks slightly modified. What social engineering tactic is
being used?
A. Whaling
B. Vishing
C. Baiting
ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.
*Core Domains*
*• Access Control Systems and Methodology*
*• Cryptographic Concepts and Applications*
*• Network Protocols and Packet Analysis*
*• Windows and Linux Host Security*
*• Incident Response and Vulnerability Management*
*• Cloud Security and Virtualization*
*• Defense-in-Depth and Security Architecture*
*• Governance, Risk, Compliance, and Ethics*
*Introduction*
*The GIAC Security Essentials assessment validates a candidate's mastery of information security beyon
SECTION ONE: QUESTIONS 1–100
Question 1
An administrator discovers that a database server containing sensitive customer records is accessible
directly from the public internet via port 1433. Which security architecture principle has been violated?
A. Defense-in-depth
B. Least privilege
,C. Separation of duties
D. Fail-secure
🟢 Correct answer: A
🔴 RATIONALE: Defense-in-depth involves layering multiple security controls so that the failure of a
single control (such as a firewall rule or network segment) does not expose critical assets. Exposing a
database directly to the internet shows a lack of layered boundary defense.
Question 2
A network security analyst runs a packet capture and observes an HTTP flood targeting a web application.
The traffic originates from hundreds of distinct IP addresses distributed globally. Which type of attack is
occurring?
A. Man-in-the-middle attack
B. Distributed Denial of Service
C. Brute-force attack
D. Address Resolution Protocol spoofing
🟢 Correct answer: B
🔴 RATIONALE: A Distributed Denial of Service (DDoS) attack coordinates multiple compromised
systems across the globe to flood a target destination with traffic, overwhelming its capacity and
exhausting resources.
Question 3
An organization is designing a cryptographic standard for securing internal web traffic. They need an
encryption algorithm that provides high speed and efficiency for large volumes of data. Which of the
following should they select?
A. RSA
B. ECC
C. AES
D. Diffie-Hellman
🟢 Correct answer: C
,🔴 RATIONALE: The Advanced Encryption Standard (AES) is a symmetric encryption algorithm, making
it vastly faster and more efficient at encrypting large volumes of data compared to asymmetric algorithms
like RSA, ECC, or Diffie-Hellman.
Question 4
A company wants to prevent employees from installing unauthorized software on corporate laptops.
Which of the following technical solutions provides the most robust control?
A. Implementing an acceptable use policy
B. Running weekly vulnerability scans
C. Deploying application blocklisting
D. Implementing application allowlisting
🟢 Correct answer: D
🔴 RATIONALE: Application allowlisting is a proactive endpoint security practice that permits only explicit,
approved binaries to execute on a system, blocking all unauthorized software by default. Blocklisting is
reactive and easily bypassed by renaming or modifying files.
Question 5
During an audit, a security team finds that system administrators share a single "root" account to perform
emergency updates on Linux servers. Which fundamental security objective is compromised?
A. Confidentiality
B. Integrity
C. Accountability
D. Availability
🟢 Correct answer: C
🔴 RATIONALE: Accountability requires that every action on a system can be definitively traced back to a
specific individual. Sharing a privileged account eliminates individual attribution, destroying accountability.
Question 6
A standard Ethernet frame header contains which type of addressing information to guide local network
delivery?
, A. IP addresses
B. MAC addresses
C. TCP port numbers
D. Logical block addresses
🟢 Correct answer: B
🔴 RATIONALE: Media Access Control (MAC) addresses operate at Data Link Layer (Layer 2) of the OSI
model and are contained in the Ethernet frame header to direct traffic between nodes on the same local
network segment.
Question 7
A company needs to comply with the Payment Card Industry Data Security Standard (PCI DSS). During a
review, they notice primary account numbers (PAN) are stored in plain text files. What action is required to
meet compliance?
A. Compress the plain text files using a zip utility
B. Render the PAN unreadable using strong cryptography
C. Move the plain text files to a hidden network share
D. Instruct employees to delete old card numbers manually
🟢 Correct answer: B
🔴 RATIONALE: PCI DSS strictly mandates that the Primary Account Number (PAN) must be rendered
unreadable anywhere it is stored, which is typically achieved through strong encryption, hashing, or
tokenization.
Question 8
An employee receives an urgent email claiming to be from the company CEO, demanding an immediate
wire transfer to a new vendor. The email address looks slightly modified. What social engineering tactic is
being used?
A. Whaling
B. Vishing
C. Baiting