TechNuggets Academy

Security Policy, Risk Management, and Active Defense

Free GIAC Security Essentials practice — 6 questions on Security Policy, Risk Management, and Active Defense, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Policy, Risk Management, and Active Defense
A risk assessment values a critical database server at $500,000. A ransomware attack against this class of server has an exposure factor of 40% and an annualized rate of occurrence of 0.5 (once every two years). What is the Annualized Loss Expectancy (ALE)?
SLE = Asset Value x EF = $500,000 x 0.40 = $200,000. ALE = SLE x ARO = $200,000 x 0.5 = $100,000.
Question 2 of 6 · Security Policy, Risk Management, and Active Defense
A security team wants to detect attackers who have already gained a foothold and are attempting lateral movement using stolen credentials, without adding monitoring overhead to production authentication systems. Which active defense technique BEST achieves this?
A honeytoken account has no legitimate purpose, so any use of it is a high-fidelity indicator of compromise or lateral movement, and it requires no additional log volume on production systems.
Question 3 of 6 · Security Policy, Risk Management, and Active Defense
An analyst configures a SIEM alert that fires on every failed login attempt across the environment. Within one hour the SOC receives over 10,000 alerts, most caused by mistyped passwords, and genuine brute-force attempts go unnoticed. Which correlation rule change BEST addresses this?
Correlating failed logins by source, count, and distinct target accounts within a tight time window filters out isolated typos while surfacing brute-force and password-spray patterns, reducing false positives without losing detection capability.
Question 4 of 6 · Security Policy, Risk Management, and Active Defense
Which policy document type defines the MANDATORY minimum security configuration settings that must be applied to all servers of a given operating system before deployment?
A baseline defines the mandatory minimum secure configuration for a specific platform or system type (e.g., a hardened Windows Server baseline) that must be met before deployment.
Question 5 of 6 · Security Policy, Risk Management, and Active Defense
A DevOps team runs application containers with the --privileged flag and the root user to simplify debugging. A later penetration test confirms container breakout to the host OS is possible. Which mitigation BEST reduces this risk while preserving normal application functionality?
Removing --privileged, dropping unneeded kernel capabilities, and running as a non-root user directly reduces the container's ability to interact with and escape to the host, following least-privilege container hardening principles.
Question 6 of 6 · Security Policy, Risk Management, and Active Defense
During an active intrusion, the incident response team identifies the external IP address of the attacker's command-and-control server. A junior analyst proposes launching a denial-of-service attack against that external server to stop ongoing exfiltration. Which statement BEST reflects appropriate active defense practice?
Active defense, as taught in GSEC, emphasizes deception, annoyance, and attribution within the organization's own environment; taking offensive action against external systems ('hacking back') carries serious legal risk (e.g., under the CFAA) and is not a sanctioned incident response practice.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →