GIAC FOUNDATIONAL CYBERSECURITY
TECHNOLOGIES (GFACT) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. Which security principle is primarily concerned with preventing
unauthorized disclosure of information?
A. Availability
B. Integrity
C. Confidentiality
D. Non-repudiation
Answer: C. Confidentiality
Rationale: Confidentiality ensures that information is accessible only
to authorized individuals, systems, or processes. Encryption, access
controls, data classification, and authentication mechanisms can all
support confidentiality. Integrity instead protects against unauthorized
modification, while availability focuses on ensuring authorized users
can access resources when needed.
2. A company requires employees to enter a username, password,
and one-time code generated by an authenticator application. Which
security concept is being implemented?
A. Single sign-on
B. Multi-factor authentication
C. Role-based access control
D. Mandatory access control
1
,Answer: B. Multi-factor authentication
Rationale: Multi-factor authentication requires authentication factors
from multiple categories, such as something you know, something you
have, or something you are. A password represents something you
know, while a code generated by an authenticator application
generally represents something you have because possession of the
enrolled device is required.
3. Which of the following is an example of an authentication factor
based on “something you are”?
A. Password
B. Smart card
C. Fingerprint
D. PIN
Answer: C. Fingerprint
Rationale: Biometrics such as fingerprints, facial characteristics, iris
patterns, and voice characteristics are examples of “something you
are.” Passwords and PINs are knowledge factors, while smart cards
and hardware security tokens are possession factors.
4. A security administrator gives users access only to the systems
necessary to perform their jobs. Which principle is being applied?
A. Defense in depth
B. Least privilege
C. Open access
D. Security through obscurity
Answer: B. Least privilege
2
,Rationale: Least privilege means users, applications, and processes
should receive only the permissions required to perform authorized
tasks. This reduces the potential impact of compromised accounts,
malicious insiders, and exploited applications.
5. Which protocol is primarily responsible for translating domain
names such as example.com into IP addresses?
A. DHCP
B. DNS
C. SSH
D. SMTP
Answer: B. DNS
Rationale: The Domain Name System translates human-readable
domain names into IP addresses and performs other name-resolution
functions. DHCP dynamically assigns network configuration
information such as IP addresses, while SMTP is used for email
transfer and SSH provides secure remote administration.
6. Which protocol is commonly used to securely administer a Linux
server remotely?
A. Telnet
B. FTP
C. SSH
D. HTTP
Answer: C. SSH
Rationale: Secure Shell provides encrypted remote access and
administration. SSH protects credentials and interactive sessions
against many forms of network interception. Telnet provides remote
3
, terminal access without modern encryption and is therefore unsuitable
for secure administration across untrusted networks.
7. Which TCP characteristic allows a connection-oriented
communication session to be established before application data is
transmitted?
A. Three-way handshake
B. Broadcast discovery
C. ARP poisoning
D. DNS recursion
Answer: A. Three-way handshake
Rationale: TCP establishes a connection using the SYN, SYN-ACK,
and ACK sequence. This handshake synchronizes sequence numbers
and establishes the logical connection before normal TCP data
transfer occurs.
8. A packet contains a source IP address, destination IP address,
and a TTL value. At which OSI layer does IP primarily operate?
A. Physical
B. Data Link
C. Network
D. Application
Answer: C. Network
Rationale: Internet Protocol operates primarily at the OSI Network
layer, Layer 3. IP provides logical addressing and routing between
networks. Ethernet frames operate primarily at Layer 2, while
protocols such as HTTP operate at the Application layer.
4
TECHNOLOGIES (GFACT) EXAM WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1. Which security principle is primarily concerned with preventing
unauthorized disclosure of information?
A. Availability
B. Integrity
C. Confidentiality
D. Non-repudiation
Answer: C. Confidentiality
Rationale: Confidentiality ensures that information is accessible only
to authorized individuals, systems, or processes. Encryption, access
controls, data classification, and authentication mechanisms can all
support confidentiality. Integrity instead protects against unauthorized
modification, while availability focuses on ensuring authorized users
can access resources when needed.
2. A company requires employees to enter a username, password,
and one-time code generated by an authenticator application. Which
security concept is being implemented?
A. Single sign-on
B. Multi-factor authentication
C. Role-based access control
D. Mandatory access control
1
,Answer: B. Multi-factor authentication
Rationale: Multi-factor authentication requires authentication factors
from multiple categories, such as something you know, something you
have, or something you are. A password represents something you
know, while a code generated by an authenticator application
generally represents something you have because possession of the
enrolled device is required.
3. Which of the following is an example of an authentication factor
based on “something you are”?
A. Password
B. Smart card
C. Fingerprint
D. PIN
Answer: C. Fingerprint
Rationale: Biometrics such as fingerprints, facial characteristics, iris
patterns, and voice characteristics are examples of “something you
are.” Passwords and PINs are knowledge factors, while smart cards
and hardware security tokens are possession factors.
4. A security administrator gives users access only to the systems
necessary to perform their jobs. Which principle is being applied?
A. Defense in depth
B. Least privilege
C. Open access
D. Security through obscurity
Answer: B. Least privilege
2
,Rationale: Least privilege means users, applications, and processes
should receive only the permissions required to perform authorized
tasks. This reduces the potential impact of compromised accounts,
malicious insiders, and exploited applications.
5. Which protocol is primarily responsible for translating domain
names such as example.com into IP addresses?
A. DHCP
B. DNS
C. SSH
D. SMTP
Answer: B. DNS
Rationale: The Domain Name System translates human-readable
domain names into IP addresses and performs other name-resolution
functions. DHCP dynamically assigns network configuration
information such as IP addresses, while SMTP is used for email
transfer and SSH provides secure remote administration.
6. Which protocol is commonly used to securely administer a Linux
server remotely?
A. Telnet
B. FTP
C. SSH
D. HTTP
Answer: C. SSH
Rationale: Secure Shell provides encrypted remote access and
administration. SSH protects credentials and interactive sessions
against many forms of network interception. Telnet provides remote
3
, terminal access without modern encryption and is therefore unsuitable
for secure administration across untrusted networks.
7. Which TCP characteristic allows a connection-oriented
communication session to be established before application data is
transmitted?
A. Three-way handshake
B. Broadcast discovery
C. ARP poisoning
D. DNS recursion
Answer: A. Three-way handshake
Rationale: TCP establishes a connection using the SYN, SYN-ACK,
and ACK sequence. This handshake synchronizes sequence numbers
and establishes the logical connection before normal TCP data
transfer occurs.
8. A packet contains a source IP address, destination IP address,
and a TTL value. At which OSI layer does IP primarily operate?
A. Physical
B. Data Link
C. Network
D. Application
Answer: C. Network
Rationale: Internet Protocol operates primarily at the OSI Network
layer, Layer 3. IP provides logical addressing and routing between
networks. Ethernet frames operate primarily at Layer 2, while
protocols such as HTTP operate at the Application layer.
4