Free GIAC Security Essentials practice — 6 questions on Vulnerability Management and Security Assessment, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Vulnerability Management and Security Assessment
Your team has change-control approval to remediate only two vulnerabilities this week. Vulnerability A: CVSS v3.1 base score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), found on an internal file server unreachable from the internet, protected by network segmentation, with no known exploit activity. Vulnerability B: CVSS v3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), found on an internet-facing web server, with threat intelligence confirming public exploit code and active worm activity. Given limited remediation capacity, which should be prioritized FIRST?
Risk-based remediation combines CVSS base score with environmental and threat context. Vulnerability B is internet-facing with confirmed active exploitation (public exploit + worm activity), making real-world exploitability and impact far higher than the isolated, segmented Vulnerability A despite its higher base score. GSEC emphasizes contextual risk over raw CVSS numbers alone.
Question 2 of 6 · Vulnerability Management and Security Assessment
During an authorized internal penetration test, the team gains access to a workstation on the same network segment as in-scope systems, but the host is not listed in the signed Rules of Engagement or scope document. Per standard penetration testing methodology, what is the CORRECT next action?
Rules of Engagement define legal and contractual scope boundaries. Testing or pivoting through an out-of-scope system without authorization exposes both the tester and client to legal and operational risk. Proper methodology requires halting activity on the unauthorized host and escalating to the point of contact for clarification before continuing.
Question 3 of 6 · Vulnerability Management and Security Assessment
A security team wants a vulnerability scan of internal Windows servers that accurately identifies missing OS/application patches, weak local configuration settings, and exact installed software versions, while minimizing false positives. Which scanning approach BEST meets this requirement?
Credentialed scanning allows the scanner to authenticate locally and query the registry, installed software inventory, patch levels, and configuration settings directly, producing far more accurate results with significantly fewer false positives than banner-based or network-only detection.
Question 4 of 6 · Vulnerability Management and Security Assessment
An analyst must complete a full TCP port scan of hosts on a segment protected by an IPS known to reset connections after detecting rapid, incomplete TCP handshakes. The analyst needs to minimize detection and avoid triggering connection resets while still completing the scan. Which Nmap configuration is MOST appropriate?
Reducing scan speed with a slower timing template (-T2) and adding an explicit delay between probes lowers the packet rate below common IPS thresholds for incomplete-handshake detection, allowing the SYN scan to complete with fewer resets or blocks.
Question 5 of 6 · Vulnerability Management and Security Assessment
Which statement BEST differentiates a vulnerability assessment from a penetration test within a formal security assessment engagement?
A vulnerability assessment focuses on discovery, identification, and prioritization of weaknesses (largely via scanning), while a penetration test intentionally exploits vulnerabilities to validate real-world impact, chain findings, and test detection/response capability — a key distinction tested on GSEC.
Question 6 of 6 · Vulnerability Management and Security Assessment
A vulnerability scanner reports a critical finding of 'Remote Code Execution in Apache Struts' on a production web server. Manual verification confirms the Struts framework is not installed and the flagged port belongs to an unrelated custom application. What is the CORRECT next action?
After manual verification confirms the finding does not apply, proper vulnerability management practice is to document it as a false positive with justification (for audit trail and future scan tuning) and review scanner configuration/plugins to reduce recurrence — not to overreact or silently discard the finding.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.