TechNuggets Academy
GSEC

Free GIAC Security Essentials Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$97911 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Defense-in-Depth and Defensible Network Architecture
A financial services company discovers that an attacker modified transaction records in a database without authorization, but the data remained accessible and no data was disclosed to unauthorized parties. Which component of the CIA triad was PRIMARILY violated?
Unauthorized modification of data is a direct violation of integrity, which concerns the accuracy and trustworthiness of data.
Question 2 of 12 · Cryptography and PKI
A financial services company runs a high-traffic public web application and wants TLS clients to be able to verify the server certificate's revocation status without introducing added latency from contacting the CA's OCSP responder during every handshake. Which mechanism BEST meets this requirement?
OCSP stapling has the server periodically fetch a signed OCSP response from the CA and attach ('staple') it to the TLS handshake, so the client gets revocation status instantly without an extra round trip to the CA, and reduces load on the OCSP responder.
Question 3 of 12 · Networking, Protocols, and Network Security
A network analyst reviews a packet capture and finds a large volume of TCP packets with the SYN and ACK flags set arriving at an internal host from hundreds of different external IP addresses on port 80. No corresponding SYN packets were ever sent from the internal host to those addresses. What does this traffic pattern MOST likely indicate?
Unsolicited SYN-ACK packets arriving without a preceding SYN violate the normal TCP three-way handshake. This is the signature of 'backscatter' — an attacker elsewhere spoofed this host's IP as the source of SYN packets sent to many external hosts as part of a SYN flood DoS attack, and those hosts' SYN-ACK replies are returning to the spoofed (victim) address.
Question 4 of 12 · Access Control, Authentication, and Password Security
A Windows domain administrator discovers that an attacker who compromised a workstation was able to authenticate to other servers using only the NTLM password hash extracted from memory, without ever knowing the plaintext password. Which control BEST prevents this attack technique going forward?
Credential Guard isolates LSASS secrets in a protected virtualized container, and unique local admin passwords (e.g., via LAPS) prevent an attacker from reusing a stolen hash to move laterally to other machines — directly mitigating pass-the-hash.
Question 5 of 12 · Incident Handling and Response
A SOC analyst discovers unusual outbound traffic from a workstation and begins reviewing logs to determine which systems have been affected, the extent of attacker access, and what data may have been exposed, without yet taking any action to stop the activity. Which phase of the incident handling process is the analyst performing?
Identification includes confirming an incident occurred and determining its scope, systems affected, and data exposure before any action is taken to stop or remove the threat.
Question 6 of 12 · Linux Security
A Linux security analyst runs `find / -perm -4000 -type f 2>/dev/null` and discovers a SUID-root binary in /tmp that is not part of the standard OS installation. What is the BEST immediate action?
Stripping the SUID bit immediately neutralizes the privilege-escalation risk while keeping the file intact for analysis (hashing, strings, timeline correlation) — the core GSEC hands-on incident response approach.
Question 7 of 12 · Windows Security
A domain has a GPO linked at the domain level that disables USB storage devices. An OU containing the Finance workstations has a separate GPO linked directly to that OU which enables USB storage devices. Both GPOs are set to 'Enabled' with no Enforced or Block Inheritance settings applied. Which policy setting will actually apply to the Finance workstations?
Group Policy is processed in LSDOU order (Local, Site, Domain, OU), and later-processed GPOs override earlier ones when settings conflict. Since OU is processed last, the OU-linked GPO enabling USB storage wins unless Enforced or Block Inheritance is used.
Question 8 of 12 · Endpoint Security and Malicious Code
A security engineer wants to allow only digitally signed executables from a specific trusted publisher to run on Windows endpoints, while automatically permitting future updates from that same vendor without creating a new rule for every version. Which AppLocker rule condition should be used?
Publisher conditions use the digital signature (publisher name, product name, and optionally version range) embedded in signed binaries, allowing the rule to survive vendor updates automatically as long as the file remains signed by the same publisher.
Question 9 of 12 · Vulnerability Management and Security Assessment
A security team wants to identify missing patches and configuration weaknesses on internal Windows servers with the lowest possible rate of false negatives. Which scanning approach BEST meets this requirement?
Credentialed (authenticated) scans log into the target using valid credentials, allowing the scanner to directly query patch levels, installed software, and configuration settings, producing far more accurate results with fewer false negatives than external checks alone.
Question 10 of 12 · Web Communication and Cloud Security
A company runs virtual machines on an IaaS cloud platform. Under the shared responsibility model, who is responsible for patching the guest operating system running on those VMs?
In the IaaS shared responsibility model, the cloud provider secures the physical hardware, virtualization layer, and network infrastructure, while the customer is responsible for the guest OS, applications, middleware, and data — including patching.
Question 11 of 12 · Security Policy, Risk Management, and Active Defense
A company's e-commerce database server is valued at $500,000. A risk assessment determines that a successful ransomware attack would destroy 20% of the asset's value (exposure factor) and that such an attack is expected to occur once every two years (ARO of 0.5). What is the Annualized Loss Expectancy (ALE)?
SLE = Asset Value x EF = $500,000 x 0.20 = $100,000. ALE = SLE x ARO = $100,000 x 0.5 = $50,000.
Question 12 of 12 · Defense-in-Depth and Defensible Network Architecture
A security architect is designing a defensible network architecture and wants to ensure that if a perimeter firewall is bypassed, the attacker still cannot move freely to critical internal systems. Which design principle BEST achieves this goal?
Internal segmentation creates additional choke points, limiting lateral movement even after perimeter compromise — a core defense-in-depth principle.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

GSEC exam — quick answers

How much does the GSEC exam cost?

The exam fee is approximately $979 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 11 domains: Defense-in-Depth and Defensible Network Architecture (Objective group (GIAC does not publish percentage weights)), Cryptography and PKI (Objective group (GIAC does not publish percentage weights)), Networking, Protocols, and Network Security (Objective group (GIAC does not publish percentage weights)), Access Control, Authentication, and Password Security (Objective group (GIAC does not publish percentage weights)), Incident Handling and Response (Objective group (GIAC does not publish percentage weights)), Linux Security (Objective group (GIAC does not publish percentage weights)), Windows Security (Objective group (GIAC does not publish percentage weights)), Endpoint Security and Malicious Code (Objective group (GIAC does not publish percentage weights)), Vulnerability Management and Security Assessment (Objective group (GIAC does not publish percentage weights)), Web Communication and Cloud Security (Objective group (GIAC does not publish percentage weights)), Security Policy, Risk Management, and Active Defense (Objective group (GIAC does not publish percentage weights)). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Defense-in-Depth and Defensible Network Architecture →Cryptography and PKI →Networking, Protocols, and Network Security →Access Control, Authentication, and Password Security →Incident Handling and Response →Linux Security →Windows Security →Endpoint Security and Malicious Code →Vulnerability Management and Security Assessment →Web Communication and Cloud Security →Security Policy, Risk Management, and Active Defense →