GIAC Security Essentials (GSEC) Exam
(AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of information security is to protect:
A. Only computer hardware
B. The confidentiality, integrity, and availability (CIA) of information
C. Internet bandwidth
D. Software licenses
Correct Answer: B
Rationale: The CIA triad forms the foundation of information security.
2. Which component of the CIA triad ensures that information is accurate and
unaltered?
A. Availability
B. Integrity
C. Confidentiality
,D. Authentication
Correct Answer: B
Rationale: Integrity protects data from unauthorized modification.
3. Which security principle grants users only the permissions necessary to
perform their duties?
A. Separation of Duties
B. Least Privilege
C. Defense in Depth
D. Need to Share
Correct Answer: B
Rationale: Least privilege minimizes the attack surface by limiting permissions.
4. Defense in Depth refers to:
A. Using multiple layers of security controls
B. Installing one powerful firewall
C. Encrypting every file
D. Using only antivirus software
Correct Answer: A
Rationale: Multiple security layers reduce the likelihood of successful attacks.
5. Which type of control is intended to stop security incidents before they
occur?
A. Detective
,B. Preventive
C. Corrective
D. Recovery
Correct Answer: B
Rationale: Preventive controls reduce the likelihood of incidents.
6. Risk is generally calculated as:
A. Threat × Vulnerability × Impact
B. Password × Encryption
C. CPU × Memory
D. Users × Devices
Correct Answer: A
Rationale: Risk depends on threats exploiting vulnerabilities and the resulting impact.
7. Which option is considered a risk treatment strategy?
A. Accept
B. Avoid
C. Mitigate
D. All of the above
Correct Answer: D
Rationale: Organizations may accept, avoid, mitigate, or transfer risk.
8. A vulnerability is best defined as:
, A. A weakness that can be exploited
B. An attacker
C. A firewall rule
D. A software license
Correct Answer: A
Rationale: Vulnerabilities create opportunities for compromise.
9. A threat is:
A. Anything capable of exploiting a vulnerability
B. A security control
C. An encryption algorithm
D. A password policy
Correct Answer: A
Rationale: Threats exploit weaknesses to cause harm.
10. Which document identifies organizational security requirements?
A. Security Policy
B. Device Driver
C. Patch File
D. BIOS Configuration
Correct Answer: A
Rationale: Security policies define organizational expectations and requirements.
(AGACNP-C) 2026–2027 |
Comprehensive Question Practice Test
with Answers & Rationales| Free Pdf
Access
1. The primary objective of information security is to protect:
A. Only computer hardware
B. The confidentiality, integrity, and availability (CIA) of information
C. Internet bandwidth
D. Software licenses
Correct Answer: B
Rationale: The CIA triad forms the foundation of information security.
2. Which component of the CIA triad ensures that information is accurate and
unaltered?
A. Availability
B. Integrity
C. Confidentiality
,D. Authentication
Correct Answer: B
Rationale: Integrity protects data from unauthorized modification.
3. Which security principle grants users only the permissions necessary to
perform their duties?
A. Separation of Duties
B. Least Privilege
C. Defense in Depth
D. Need to Share
Correct Answer: B
Rationale: Least privilege minimizes the attack surface by limiting permissions.
4. Defense in Depth refers to:
A. Using multiple layers of security controls
B. Installing one powerful firewall
C. Encrypting every file
D. Using only antivirus software
Correct Answer: A
Rationale: Multiple security layers reduce the likelihood of successful attacks.
5. Which type of control is intended to stop security incidents before they
occur?
A. Detective
,B. Preventive
C. Corrective
D. Recovery
Correct Answer: B
Rationale: Preventive controls reduce the likelihood of incidents.
6. Risk is generally calculated as:
A. Threat × Vulnerability × Impact
B. Password × Encryption
C. CPU × Memory
D. Users × Devices
Correct Answer: A
Rationale: Risk depends on threats exploiting vulnerabilities and the resulting impact.
7. Which option is considered a risk treatment strategy?
A. Accept
B. Avoid
C. Mitigate
D. All of the above
Correct Answer: D
Rationale: Organizations may accept, avoid, mitigate, or transfer risk.
8. A vulnerability is best defined as:
, A. A weakness that can be exploited
B. An attacker
C. A firewall rule
D. A software license
Correct Answer: A
Rationale: Vulnerabilities create opportunities for compromise.
9. A threat is:
A. Anything capable of exploiting a vulnerability
B. A security control
C. An encryption algorithm
D. A password policy
Correct Answer: A
Rationale: Threats exploit weaknesses to cause harm.
10. Which document identifies organizational security requirements?
A. Security Policy
B. Device Driver
C. Patch File
D. BIOS Configuration
Correct Answer: A
Rationale: Security policies define organizational expectations and requirements.