GSEC EXAM QUESTIONS WITH CORRECT
ANSWERS
When |using |Pretty |Good |Privacy |(PGP) |to |digitally |sign |a |message, |the |signature |is |created |in |a
|two-step |process. |First, |the |message |to |be |signed |is |submitted |toPGP's |cryptographic |hash |
algorithm. |What |is |one |of |the |hash |algorithms |used |by |PGP |for |this |process? |- |CORRECT |
ANSWER✔✔-SHA-l
You |are |the |security |director |for |an |off-shore |banking |site. |From |a |business |perspective, |what |
is |a |major |factor |to |consider |before |running |your |new |vulnerability |scanner |against |the |
company's |business |systems? |- |CORRECT |ANSWER✔✔-It |may |generate |false |positive |results
Which |of |the |following |is |a |benefit |to |utilizing |Cygwin |for |Windows? |- |CORRECT |ANSWER✔✔-
The |ability |to |install |a |complete |Red |Hat |operating |system |Install |on |Windows.
What |technical |control |provides |the |most |critical |layer |of |defense |if |an |intruder |is |able |to |
bypass |all |physical |security |controls |and |obtain |tapes |containing |critical |data? |- |CORRECT |
ANSWER✔✔-Encryption
Two |clients |connecting |from |the |same |public |IP |address |(for |example |- |behind |the |same |NAT |
firewall) |can |connect |simultaneously |to |the |same |web |server |on |theInternet, |provided |what |
condition |is |TRUE? |- |CORRECT |ANSWER✔✔-The |client-side |source |ports |are |different.
Which |of |the |following |is |a |standard |Unix |command |that |would |most |likely |be |used |to |copy |
raw |file |system |data |for |later |forensic |analysis? |- |CORRECT |ANSWER✔✔-dd
Which |of |the |following |is |NOT |a |recommended |best |practice |for |securing |Terminal |Services |
and |Remote |Desktop? |- |CORRECT |ANSWER✔✔-Make |sure |to |allow |all |TCP |3389 |traffic |
through |the |external |firewall.
, When |an |IIS |filename |extension |is |mapped, |what |does |this |mean? |- |CORRECT |ANSWER✔✔-
The |file |and |all |the |data |from |the |browser's |request |are |handed |off |to |the |mapped |
interpreter.
Which |Linux |file |lists |every |process |that |starts |at |boot |time? |- |CORRECT |ANSWER✔✔-inittab
When |trace |route |fails |to |get |a |timely |response |for |a |packet |after |three |tries, |which |action |will
|it |take? |- |CORRECT |ANSWER✔✔-It |will |print |'* |* |*' |for |the |attempts, |increment |the |TTL |and |
try |again |until |the |maximum |hop |count.
You |are |examining |an |IP |packet |with |a |header |of |40 |bytes |in |length |and |the |value |at |byte |0 |of |
the |packet |header |is |6. |Which |of |the |following |describes |this |packet? |- |CORRECT |ANSWER✔✔-
This |is |an |IPv6 |packet; |the |protocol |encapsulated |in |the |payload |is |unspecified.
Which |of |the |following |is |a |valid |password |for |a |system |with |the |default |"Password |must |meet
|complexity |requirements" |setting |enabled |as |part |of |the |GPOPassword |policy |requirements? |-
|CORRECT |ANSWER✔✔-SaNS2006
At |what |point |in |the |Incident |Handling |process |should |an |organization |determine |its |approach |
to |notifying |law |enforcement? |- |CORRECT |ANSWER✔✔-When |preparing |policy
Which |of |the |following |is |TRUE |regarding |the |ability |of |attackers |to |eavesdrop |on |wireless |
communications? |- |CORRECT |ANSWER✔✔-B. |Eavesdropping |attacks |can |take |place |from |miles |
away.
An |employee |is |currently |logged |into |the |corporate |web |server, |without |permission. |You |log |
into |the |web |server |as |'admin" |and |look |for |the |employee's |username:"dmaul" |using |the
|"who" |command. |This |is |what |you |get |back: |- |CORRECT |ANSWER✔✔-The |contents |of |the |
utmp |file |has |been |altered
list |the |users |on |the |system
ANSWERS
When |using |Pretty |Good |Privacy |(PGP) |to |digitally |sign |a |message, |the |signature |is |created |in |a
|two-step |process. |First, |the |message |to |be |signed |is |submitted |toPGP's |cryptographic |hash |
algorithm. |What |is |one |of |the |hash |algorithms |used |by |PGP |for |this |process? |- |CORRECT |
ANSWER✔✔-SHA-l
You |are |the |security |director |for |an |off-shore |banking |site. |From |a |business |perspective, |what |
is |a |major |factor |to |consider |before |running |your |new |vulnerability |scanner |against |the |
company's |business |systems? |- |CORRECT |ANSWER✔✔-It |may |generate |false |positive |results
Which |of |the |following |is |a |benefit |to |utilizing |Cygwin |for |Windows? |- |CORRECT |ANSWER✔✔-
The |ability |to |install |a |complete |Red |Hat |operating |system |Install |on |Windows.
What |technical |control |provides |the |most |critical |layer |of |defense |if |an |intruder |is |able |to |
bypass |all |physical |security |controls |and |obtain |tapes |containing |critical |data? |- |CORRECT |
ANSWER✔✔-Encryption
Two |clients |connecting |from |the |same |public |IP |address |(for |example |- |behind |the |same |NAT |
firewall) |can |connect |simultaneously |to |the |same |web |server |on |theInternet, |provided |what |
condition |is |TRUE? |- |CORRECT |ANSWER✔✔-The |client-side |source |ports |are |different.
Which |of |the |following |is |a |standard |Unix |command |that |would |most |likely |be |used |to |copy |
raw |file |system |data |for |later |forensic |analysis? |- |CORRECT |ANSWER✔✔-dd
Which |of |the |following |is |NOT |a |recommended |best |practice |for |securing |Terminal |Services |
and |Remote |Desktop? |- |CORRECT |ANSWER✔✔-Make |sure |to |allow |all |TCP |3389 |traffic |
through |the |external |firewall.
, When |an |IIS |filename |extension |is |mapped, |what |does |this |mean? |- |CORRECT |ANSWER✔✔-
The |file |and |all |the |data |from |the |browser's |request |are |handed |off |to |the |mapped |
interpreter.
Which |Linux |file |lists |every |process |that |starts |at |boot |time? |- |CORRECT |ANSWER✔✔-inittab
When |trace |route |fails |to |get |a |timely |response |for |a |packet |after |three |tries, |which |action |will
|it |take? |- |CORRECT |ANSWER✔✔-It |will |print |'* |* |*' |for |the |attempts, |increment |the |TTL |and |
try |again |until |the |maximum |hop |count.
You |are |examining |an |IP |packet |with |a |header |of |40 |bytes |in |length |and |the |value |at |byte |0 |of |
the |packet |header |is |6. |Which |of |the |following |describes |this |packet? |- |CORRECT |ANSWER✔✔-
This |is |an |IPv6 |packet; |the |protocol |encapsulated |in |the |payload |is |unspecified.
Which |of |the |following |is |a |valid |password |for |a |system |with |the |default |"Password |must |meet
|complexity |requirements" |setting |enabled |as |part |of |the |GPOPassword |policy |requirements? |-
|CORRECT |ANSWER✔✔-SaNS2006
At |what |point |in |the |Incident |Handling |process |should |an |organization |determine |its |approach |
to |notifying |law |enforcement? |- |CORRECT |ANSWER✔✔-When |preparing |policy
Which |of |the |following |is |TRUE |regarding |the |ability |of |attackers |to |eavesdrop |on |wireless |
communications? |- |CORRECT |ANSWER✔✔-B. |Eavesdropping |attacks |can |take |place |from |miles |
away.
An |employee |is |currently |logged |into |the |corporate |web |server, |without |permission. |You |log |
into |the |web |server |as |'admin" |and |look |for |the |employee's |username:"dmaul" |using |the
|"who" |command. |This |is |what |you |get |back: |- |CORRECT |ANSWER✔✔-The |contents |of |the |
utmp |file |has |been |altered
list |the |users |on |the |system