GIAC Security Essentials (GSEC) Practice Test
Exam
1. What does the CIA triad stand for in information security?
A. Confidentiality, Integrity, Availability
B. Control, Inspection, Authorization
C. Cryptography, Identity, Access
D. Compliance, Isolation, Auditing
Answer: A
Rationale: The CIA triad represents the three core principles of
information security: confidentiality, integrity, and availability.
2. Which type of attack involves an attacker intercepting
communication between two parties?
A. Denial of service
B. Man in the middle
C. Phishing
D. SQL injection
Answer: B
,Rationale: A man in the middle attack occurs when an attacker
secretly intercepts and possibly alters communication between
two parties.
3. What is the primary purpose of a firewall?
A. To encrypt data
B. To filter network traffic based on rules
C. To scan for viruses
D. To authenticate users
Answer: B
Rationale: A firewall filters network traffic based on predefined
security rules to allow or block communications.
4. Which protocol is used for secure web browsing?
A. HTTP
B. FTP
C. HTTPS
D. Telnet
Answer: C
,Rationale: HTTPS uses TLS to encrypt web traffic between a
client and server.
5. What is the purpose of a hash function in security?
A. To encrypt data
B. To verify data integrity
C. To compress data
D. To route data
Answer: B
Rationale: Hash functions produce a fixed-length value used to
verify that data has not been altered.
6. Which type of malware self-replicates without user
interaction?
A. Trojan
B. Worm
C. Adware
D. Spyware
Answer: B
, Rationale: A worm self-replicates and spreads across networks
without requiring user interaction.
7. What is the purpose of multi-factor authentication?
A. To require multiple forms of verification
B. To encrypt passwords
C. To store credentials
D. To audit access
Answer: A
Rationale: Multi-factor authentication requires two or more
verification factors to grant access.
8. Which port does SSH use by default?
A. 21
B. 22
C. 23
D. 25
Answer: B
Rationale: SSH uses TCP port 22 by default for secure remote
access.
Exam
1. What does the CIA triad stand for in information security?
A. Confidentiality, Integrity, Availability
B. Control, Inspection, Authorization
C. Cryptography, Identity, Access
D. Compliance, Isolation, Auditing
Answer: A
Rationale: The CIA triad represents the three core principles of
information security: confidentiality, integrity, and availability.
2. Which type of attack involves an attacker intercepting
communication between two parties?
A. Denial of service
B. Man in the middle
C. Phishing
D. SQL injection
Answer: B
,Rationale: A man in the middle attack occurs when an attacker
secretly intercepts and possibly alters communication between
two parties.
3. What is the primary purpose of a firewall?
A. To encrypt data
B. To filter network traffic based on rules
C. To scan for viruses
D. To authenticate users
Answer: B
Rationale: A firewall filters network traffic based on predefined
security rules to allow or block communications.
4. Which protocol is used for secure web browsing?
A. HTTP
B. FTP
C. HTTPS
D. Telnet
Answer: C
,Rationale: HTTPS uses TLS to encrypt web traffic between a
client and server.
5. What is the purpose of a hash function in security?
A. To encrypt data
B. To verify data integrity
C. To compress data
D. To route data
Answer: B
Rationale: Hash functions produce a fixed-length value used to
verify that data has not been altered.
6. Which type of malware self-replicates without user
interaction?
A. Trojan
B. Worm
C. Adware
D. Spyware
Answer: B
, Rationale: A worm self-replicates and spreads across networks
without requiring user interaction.
7. What is the purpose of multi-factor authentication?
A. To require multiple forms of verification
B. To encrypt passwords
C. To store credentials
D. To audit access
Answer: A
Rationale: Multi-factor authentication requires two or more
verification factors to grant access.
8. Which port does SSH use by default?
A. 21
B. 22
C. 23
D. 25
Answer: B
Rationale: SSH uses TCP port 22 by default for secure remote
access.