Achieve the GSEC Exam Best Results with Help from GIAC Certified Experts [Q98-Q114]

Share

Achieve the GSEC Exam Best Results with Help from GIAC Certified Experts

Provide GSEC Practice Test Engine for Preparation


GIAC GSEC (GIAC Security Essentials Certification) Certification Exam is a well-known and respected certification in the cybersecurity industry. GIAC Security Essentials Certification certification is designed to measure the knowledge and skills of a candidate in the fundamental principles of information security. The GSEC certification is aimed at professionals who want to demonstrate their proficiency in foundational cybersecurity concepts.


GIAC GSEC (GIAC Security Essentials Certification) Exam is a credential that validates the candidate's knowledge and expertise in various aspects of information security. GIAC Security Essentials Certification certification is offered by the Global Information Assurance Certification (GIAC), a leading organization in the field of cybersecurity. GSEC exam covers a wide range of topics, including network security, security policies and procedures, cryptography, risk management, and incident response. GIAC Security Essentials Certification certification is designed for professionals who are involved in information security, such as security analysts, network administrators, and IT managers.

 

NEW QUESTION # 98
Which of the following choices accurately describes how PGP works when encrypting email?

  • A. PGP creates a random asymmetric key that it uses to encrypt the message, then encrypts this key with the recipient's public key
  • B. PGP encrypts the message with the recipients public key, then encrypts this key with a random symmetric key.
  • C. PGP creates a random symmetric key that it uses to encrypt the message, then encrypts this key with the recipient's public key
  • D. PGP encrypts the message with the recipients public key, then encrypts this key with a random asymmetric key.

Answer: A


NEW QUESTION # 99
What is the purpose of notifying stakeholders prior to a scheduled vulnerability scan?

  • A. Risk of system crashes and security alerts.
  • B. Risk of applying untested patches.
  • C. Risk of deletion of backup files.
  • D. Risk of modified application configuration files.

Answer: A


NEW QUESTION # 100
When designing wireless networks, one strategy to consider is implementing security mechanisms at all layers of the OSI model. Which of the following protection mechanisms would protect layer 1?

  • A. Limit RF coverage
  • B. Hardening applications
  • C. Enabling strong encryption
  • D. Employing firewalls

Answer: A


NEW QUESTION # 101
Which of the following processes is used by remote users to make a secure connection to internal resources after establishing an Internet connection?

  • A. Packet sniffing
  • B. Spoofing
  • C. Packet filtering
  • D. Tunneling

Answer: D


NEW QUESTION # 102
Which of the following statements are true about satellite broadband Internet access? Each correct answer represents a complete solution. Choose two.

  • A. It is among the least expensive way of gaining broadband Internet access.
  • B. It is among the most expensive way of gaining broadband Internet access.
  • C. This type of internet access has high latency compared to other broadband services.
  • D. This type of internet access has low latency compared to other broadband services.

Answer: B,C


NEW QUESTION # 103
Which of the following is a name, symbol, or slogan with which a product is identified?

  • A. Trademark
  • B. Patent
  • C. Trade secret
  • D. Copyright

Answer: A


NEW QUESTION # 104
Which of the following is a potential WPA3 security issue?

  • A. Traffic decryption with PSK
  • B. Backward compatibility
  • C. Disassociate frame DoS
  • D. Short key lengths

Answer: B


NEW QUESTION # 105
Which of the following components come under the network layer of the OSI model? Each correct answer represents a complete solution. Choose two.

  • A. Hub
  • B. Firewalls
  • C. Routers
  • D. MAC addresses

Answer: B,C


NEW QUESTION # 106
Wired Equivalent Privacy (WEP) is a security protocol for wireless local area networks (WLANs). It has two components, authentication and encryption. It provides security equivalent to wired networks for wireless networks. WEP encrypts data on a wireless network by using a fixed secret key. Which of the following statements are true about WEP? Each correct answer represents a complete solution. Choose all that apply.

  • A. WEP uses the RC4 encryption algorithm.
  • B. Automated tools such as AirSnort are available for discovering WEP keys.
  • C. It provides better security than the Wi-Fi Protected Access protocol.
  • D. The Initialization Vector (IV) field of WEP is only 24 bits long.

Answer: A,B,D


NEW QUESTION # 107
Which of the following records is the first entry in a DNS database file?

  • A. MX
  • B. CNAME
  • C. SOA
  • D. SRV

Answer: C


NEW QUESTION # 108
Which of the following frequencies is used by the wireless standard 802.11a?

  • A. 2.4 Ghz
  • B. 2 Ghz
  • C. 5 Ghz
  • D. 1 Ghz

Answer: C


NEW QUESTION # 109
Two clients connecting from the same public IP address (for example - behind the same NAT firewall) can connect simultaneously to the same web server on the Internet, provided what condition is TRUE?

  • A. The client-side source ports are different.
  • B. The clients are on different subnets.
  • C. The server is not using a well-known port.
  • D. The server is on a different network.

Answer: A

Explanation:
Explanation


NEW QUESTION # 110
Why would someone use port 80 for deployment of unauthorized services?

  • A. HTTP traffic is usually allowed outbound to port 80 through the firewall in most environments.
  • B. This is a technique commonly used to perform a denial of service on the local web server.
  • C. If someone were to randomly browse to the rogue port 80 service they could be compromised.
  • D. Google will detect the service listing on port 80 and post a link, so that people all over the world will surf to the rogue service.

Answer: A

Explanation:
Explanation/Reference:


NEW QUESTION # 111
Why would someone use port 80 for deployment of unauthorized services?

  • A. HTTP traffic is usually allowed outbound to port 80 through the firewall in most environments.
  • B. This is a technique commonly used to perform a denial of service on the local web server.
  • C. If someone were to randomly browse to the rogue port 80 service they could be compromised.
  • D. Google will detect the service listing on port 80 and post a link, so that people all over the world will surf to the rogue service.

Answer: A


NEW QUESTION # 112
Which of the following TCP dump output lines indicates the first step in the TCP 3-way handshake?

  • A. 07:09:43.368615 download.net 39904 > ftp.com.21: S 733381829:733381829(0) win 8760 <mss 1460> (DF)
  • B. 09:09:22.346383 ftp.com.21 > download.net.39904: , rst 1 win 2440(DF)
  • C. 07:09:43.370355 download.net.39904 > ftp.com.21: , ack 1 win 8760 (DF)
  • D. 07:09:43.370302 ftp.com.21 > download.net.39904: S 1192930639:1192930639(0} ack 733381830 win 1024 <mss 1460> (DF)

Answer: A


NEW QUESTION # 113
Use Hashcat to crack a local shadow file. What Is the password for the user account AGainsboro?
Hints
* The shadow file (shadow) and Hashcat wordlist (gsecwordlist.txt) are located in the directory /home /giac /PasswordHashing/
* Run Hashcat in straight mode (flag -a 0) to crack the MD5 hashes (flag -m 500) In the shadow file.
* Use the hash values from the Hashcat output file and the shadow file to match the cracked password with the user name.
* If required, a backup copy of the original files can be found in the shadowbackup directory.

  • A. jason66
  • B. QX689PJ688
  • C. Noregrets2
  • D. Learn2Write
  • E. Volcano
  • F. Th 3D5@60n
  • G. YOuRF ether?
  • H. symbiote
  • I. LlqMM@qe
  • J. 0

Answer: B


NEW QUESTION # 114
......

Detailed New GSEC Exam Questions for Concept Clearance: https://www.surepassexams.com/GSEC-exam-bootcamp.html

GSEC Exam Preparation Material with New GSEC Dumps Questions.: https://drive.google.com/open?id=1IT-mpRmabJz-2qRs_ANS5sOIyFXeLuLW