GIAC Security Essentials (GSEC) Practice Test
Gana confianza para GIAC Security Essentials (GSEC). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.
Probar una preguntaDescripción y detalles del examen
The GIAC Security Essentials (GSEC) certification is a globally recognized, vendor-neutral credential that validates a practitioner's foundational knowledge and hands-on skills in information security. Administered by the Global Information Assurance Certification (GIAC) organization, the GSEC exam assesses core competencies across multiple security domains, ensuring certified professionals possess the practical abilities required to secure modern IT environments. Earning the GSEC demonstrates to employers a verified understanding of essential security concepts, including network defense, cryptography, access controls, and hardening of Windows and Linux systems. It is often a prerequisite for intermediate and advanced security roles, serving as a critical benchmark for hiring managers and a cornerstone for building a comprehensive security career. The certification is aligned with the SANS Institute's training, emphasizing real-world application over theoretical knowledge, which makes GSEC holders immediately valuable in operational security teams.
Preguntas de Muestra
Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.
A university IT team is standardizing controls across dorm networks, research labs, Microsoft 365, AWS accounts, and a public web portal. The current GSEC study scenario focuses on NIST CSF 2.0: leadership wants a common language for cyber risk governance across business units. Which response best addresses the security issue while preserving defensible operations?
Utilice las funciones de NIST CSF 2.0, incluyendo Govern, para organizar resultados y la comunicación de riesgos es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Usar solo capturas de paquetes como marco de gobernanza) es incorrecta porque la evidencia técnica sola no estructura la gobernanza de riesgos de la empresa; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.
A logistics provider has asked a new security administrator to prioritize practical changes that reduce risk without breaking warehouse operations. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?
Publicar una firma criptográfica o una huella digital sobre el instalador es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Cifrar el nombre del archivo con AES) es incorrecta porque cifrar el nombre del archivo no prueba la integridad del archivo; los candidatos que la eligen están confundiendo un concepto cercano con el riesgo específico mostrado en el escenario.
A regional hospital is preparing a 2025 cyber insurance renewal after merging two clinics. Legacy servers, cloud file sharing, and a small SOC are all in scope. The current GSEC study scenario focuses on Azure identity: a Microsoft Entra tenant has many guest users and no review of app consent grants. Which response best addresses the security issue while preserving defensible operations?
Revisar el acceso de invitados, las concesiones de consentimiento, el acceso condicional y las asignaciones de roles de privilegios es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Renombrar el nombre de pantalla de la tenencia) es incorrecta porque los cambios cosméticos no reducen el riesgo de identidad o consentimiento; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.
A SaaS startup is moving from ad hoc administration to documented baseline controls, ticketed change approvals, and repeatable incident response. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?
Publicar una firma criptográfica o un hash digital sobre el instalador es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Cifrar el nombre del archivo con AES) es incorrecta porque la cifrado del nombre del archivo no prueba la integridad del archivo; los candidatos que la eligen están confundiendo un concepto cercano con el riesgo específico mostrado en el escenario.
A manufacturer with Windows 11 laptops, Ubuntu jump hosts, and a segmented OT lab is responding to audit findings from an external assessor. The current GSEC study scenario focuses on incident response first actions: EDR reports possible ransomware on one finance laptop while the user is still connected to file shares. Which response best addresses the security issue while preserving defensible operations?
Contener el host, preservar evidencia relevante y iniciar el proceso de respuesta a incidentes es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Ejecutar una limpieza de disco completa de inmediato) es incorrecta porque borrar puede destruir evidencia antes de que se entienda el alcance y la contención; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.
Oportunidades profesionales y salario
Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.
Qué temas cubre este examen
01Access Control & Password Management
Temas
- Understand the fundamental theory of access control and the role of passwords in access control management.
Objetivos de aprendizaje
- Understand the fundamental theory of access control and the role of passwords in access control management.
02Container and MacOS Security
Temas
- Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.
Objetivos de aprendizaje
- Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.
03Cryptography
Temas
- Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.
Objetivos de aprendizaje
- Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.
04Cryptography Application
Temas
- Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.
Objetivos de aprendizaje
- Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.
05Data Loss Prevention and Mobile Device Security
Temas
- Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.
Objetivos de aprendizaje
- Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.
06Defense in Depth
Temas
- Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.
Objetivos de aprendizaje
- Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.
07Defensible Network Architecture
Temas
- Demonstrate how to architect a network to be monitored and controlled to resist intrusion.
Objetivos de aprendizaje
- Demonstrate how to architect a network to be monitored and controlled to resist intrusion.
08Endpoint Security
Temas
- Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.
Objetivos de aprendizaje
- Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.
09Enforcing Windows Security Policy
Temas
- Have a high-level understanding of the features of Group Policy and working with INF security templates.
Objetivos de aprendizaje
- Have a high-level understanding of the features of Group Policy and working with INF security templates.
10Incident Handling & Response
Temas
- Understand the concepts and processes associated with incident handling.
Objetivos de aprendizaje
- Understand the concepts and processes associated with incident handling.
11Linux Fundamentals
Temas
- Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.
Objetivos de aprendizaje
- Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.
12Linux Security and Hardening
Temas
- Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.
Objetivos de aprendizaje
- Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.
13Log Management & SIEM
Temas
- Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.
Objetivos de aprendizaje
- Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.
14Malicious Code & Exploit Mitigation
Temas
- Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.
Objetivos de aprendizaje
- Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.
15Network Security Devices
Temas
- Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.
Objetivos de aprendizaje
- Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.
16Networking & Protocols
Temas
- Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.
Objetivos de aprendizaje
- Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.
17Security Frameworks and CIS Controls
Temas
- Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.
Objetivos de aprendizaje
- Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.
18Virtualization, Cloud Security, and AI Essentials
Temas
- Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.
Objetivos de aprendizaje
- Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.
19Vulnerability Scanning and Penetration Testing
Temas
- Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.
Objetivos de aprendizaje
- Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.
20Web Communication Security
Temas
- Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.
Objetivos de aprendizaje
- Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.
21Windows Access Controls
Temas
- Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.
Objetivos de aprendizaje
- Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.
22Windows as a Service
Temas
- Understand how to manage updates for a network of Windows hosts.
Objetivos de aprendizaje
- Understand how to manage updates for a network of Windows hosts.
23Windows Automation, Auditing, and Forensics
Temas
- Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.
Objetivos de aprendizaje
- Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.
24Windows Security Infrastructure
Temas
- Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.
Objetivos de aprendizaje
- Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.
25Windows Services and Microsoft Cloud
Temas
- Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.
Objetivos de aprendizaje
- Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.
26Wireless Network Security
Temas
- Have a basic understanding of the configuration and risks of wireless networks and how to secure them.
Objetivos de aprendizaje
- Have a basic understanding of the configuration and risks of wireless networks and how to secure them.