GIAC Security Essentials (GSEC) Practice Test

189 preguntas disponibles

Gana confianza para GIAC Security Essentials (GSEC). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
180 Preguntas del examen
6 horas Límite de Tiempo
Tu práctica
189 Preguntas de práctica
3 horas 9 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 73 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de GIAC
GIAC189 preguntas de práctica
Temario verificadoVerificado con GIAC official objectivesMetadatos verificados 2026-06-11Cómo verificamos

Descripción y detalles del examen

The GIAC Security Essentials (GSEC) certification is a globally recognized, vendor-neutral credential that validates a practitioner's foundational knowledge and hands-on skills in information security. Administered by the Global Information Assurance Certification (GIAC) organization, the GSEC exam assesses core competencies across multiple security domains, ensuring certified professionals possess the practical abilities required to secure modern IT environments. Earning the GSEC demonstrates to employers a verified understanding of essential security concepts, including network defense, cryptography, access controls, and hardening of Windows and Linux systems. It is often a prerequisite for intermediate and advanced security roles, serving as a critical benchmark for hiring managers and a cornerstone for building a comprehensive security career. The certification is aligned with the SANS Institute's training, emphasizing real-world application over theoretical knowledge, which makes GSEC holders immediately valuable in operational security teams.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Security Frameworks and CIS Controls

A university IT team is standardizing controls across dorm networks, research labs, Microsoft 365, AWS accounts, and a public web portal. The current GSEC study scenario focuses on NIST CSF 2.0: leadership wants a common language for cyber risk governance across business units. Which response best addresses the security issue while preserving defensible operations?

Explicación:

Utilice las funciones de NIST CSF 2.0, incluyendo Govern, para organizar resultados y la comunicación de riesgos es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Usar solo capturas de paquetes como marco de gobernanza) es incorrecta porque la evidencia técnica sola no estructura la gobernanza de riesgos de la empresa; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.

Cryptography

A logistics provider has asked a new security administrator to prioritize practical changes that reduce risk without breaking warehouse operations. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

Explicación:

Publicar una firma criptográfica o una huella digital sobre el instalador es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Cifrar el nombre del archivo con AES) es incorrecta porque cifrar el nombre del archivo no prueba la integridad del archivo; los candidatos que la eligen están confundiendo un concepto cercano con el riesgo específico mostrado en el escenario.

Cloud, Virtualization, Containers, and AI Essentials

A regional hospital is preparing a 2025 cyber insurance renewal after merging two clinics. Legacy servers, cloud file sharing, and a small SOC are all in scope. The current GSEC study scenario focuses on Azure identity: a Microsoft Entra tenant has many guest users and no review of app consent grants. Which response best addresses the security issue while preserving defensible operations?

Explicación:

Revisar el acceso de invitados, las concesiones de consentimiento, el acceso condicional y las asignaciones de roles de privilegios es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Renombrar el nombre de pantalla de la tenencia) es incorrecta porque los cambios cosméticos no reducen el riesgo de identidad o consentimiento; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.

Cryptography

A SaaS startup is moving from ad hoc administration to documented baseline controls, ticketed change approvals, and repeatable incident response. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

Explicación:

Publicar una firma criptográfica o un hash digital sobre el instalador es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Cifrar el nombre del archivo con AES) es incorrecta porque la cifrado del nombre del archivo no prueba la integridad del archivo; los candidatos que la eligen están confundiendo un concepto cercano con el riesgo específico mostrado en el escenario.

Vulnerability Management, Web Security, and Incident Response

A manufacturer with Windows 11 laptops, Ubuntu jump hosts, and a segmented OT lab is responding to audit findings from an external assessor. The current GSEC study scenario focuses on incident response first actions: EDR reports possible ransomware on one finance laptop while the user is still connected to file shares. Which response best addresses the security issue while preserving defensible operations?

Explicación:

Contener el host, preservar evidencia relevante y iniciar el proceso de respuesta a incidentes es correcto porque aborda la brecha de control observada con una medida defensiva práctica. La distracción más plausible (Ejecutar una limpieza de disco completa de inmediato) es incorrecta porque borrar puede destruir evidencia antes de que se entienda el alcance y la contención; los candidatos que la eligen confunden un concepto cercano con el riesgo específico mostrado en el escenario.

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Access Control & Password Management

Temas

  • Understand the fundamental theory of access control and the role of passwords in access control management.

Objetivos de aprendizaje

  • Understand the fundamental theory of access control and the role of passwords in access control management.

02Container and MacOS Security

Temas

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

Objetivos de aprendizaje

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

03Cryptography

Temas

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

Objetivos de aprendizaje

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

04Cryptography Application

Temas

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

Objetivos de aprendizaje

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

05Data Loss Prevention and Mobile Device Security

Temas

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

Objetivos de aprendizaje

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

06Defense in Depth

Temas

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

Objetivos de aprendizaje

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

07Defensible Network Architecture

Temas

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

Objetivos de aprendizaje

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

08Endpoint Security

Temas

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

Objetivos de aprendizaje

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

09Enforcing Windows Security Policy

Temas

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

Objetivos de aprendizaje

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

10Incident Handling & Response

Temas

  • Understand the concepts and processes associated with incident handling.

Objetivos de aprendizaje

  • Understand the concepts and processes associated with incident handling.

11Linux Fundamentals

Temas

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

Objetivos de aprendizaje

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

12Linux Security and Hardening

Temas

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

Objetivos de aprendizaje

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

13Log Management & SIEM

Temas

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

Objetivos de aprendizaje

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

14Malicious Code & Exploit Mitigation

Temas

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

Objetivos de aprendizaje

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

15Network Security Devices

Temas

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

Objetivos de aprendizaje

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

16Networking & Protocols

Temas

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

Objetivos de aprendizaje

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

17Security Frameworks and CIS Controls

Temas

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

Objetivos de aprendizaje

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

18Virtualization, Cloud Security, and AI Essentials

Temas

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

Objetivos de aprendizaje

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

19Vulnerability Scanning and Penetration Testing

Temas

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

Objetivos de aprendizaje

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

20Web Communication Security

Temas

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

Objetivos de aprendizaje

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

21Windows Access Controls

Temas

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

Objetivos de aprendizaje

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

22Windows as a Service

Temas

  • Understand how to manage updates for a network of Windows hosts.

Objetivos de aprendizaje

  • Understand how to manage updates for a network of Windows hosts.

23Windows Automation, Auditing, and Forensics

Temas

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

Objetivos de aprendizaje

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

24Windows Security Infrastructure

Temas

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

Objetivos de aprendizaje

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

25Windows Services and Microsoft Cloud

Temas

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

Objetivos de aprendizaje

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

26Wireless Network Security

Temas

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

Objetivos de aprendizaje

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

Detalles del Examen GSEC | $949 USD | 6 horas

Código del Examen GSEC
Proveedor GIAC
Costo del Examen $949 USD
Puntaje Mínimo 73
Límite de Tiempo 6 horas
Preguntas del examen 180
Tipos de Preguntas Opción múltiple (100%)
Política de Repetición Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Formato del Examen Multiple Choice
Supervisión en Línea Disponible

Preguntas Frecuentes

¿Cuál es el público objetivo típico para la certificación GSEC?

¿En qué se diferencia el GSEC de CompTIA Security+?

¿Cuál es la ruta de preparación recomendada para el examen GSEC?

¿Cuál es el formato y la duración del examen?

¿Cuánto tiempo es válida la certificación GSEC y cuáles son los requisitos de renovación?