GIAC Security Essentials (GSEC) Practice Test

189 प्रश्न उपलब्ध

GIAC Security Essentials (GSEC) के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
180 परीक्षा प्रश्न
6 घंटे समय सीमा
आपका अभ्यास
189 अभ्यास सवाल
3 घंटे 9 मिनट अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
पार करने की सीमा 73 इस प्रमाणन के लिए प्रकाशित उत्तीर्णांक।
परीक्षा के विषय जानें GIAC से आधिकारिक उद्देश्य
GIAC189 अभ्यास प्रश्न
ब्लूप्रिंट सत्यापितGIAC official objectives के साथ जाँचा गयामेटाडेटा सत्यापित 2026-06-11हम कैसे सत्यापित करते हैं

परीक्षा का परिचय और विवरण

The GIAC Security Essentials (GSEC) certification is a globally recognized, vendor-neutral credential that validates a practitioner's foundational knowledge and hands-on skills in information security. Administered by the Global Information Assurance Certification (GIAC) organization, the GSEC exam assesses core competencies across multiple security domains, ensuring certified professionals possess the practical abilities required to secure modern IT environments. Earning the GSEC demonstrates to employers a verified understanding of essential security concepts, including network defense, cryptography, access controls, and hardening of Windows and Linux systems. It is often a prerequisite for intermediate and advanced security roles, serving as a critical benchmark for hiring managers and a cornerstone for building a comprehensive security career. The certification is aligned with the SANS Institute's training, emphasizing real-world application over theoretical knowledge, which makes GSEC holders immediately valuable in operational security teams.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

Security Frameworks and CIS Controls

A university IT team is standardizing controls across dorm networks, research labs, Microsoft 365, AWS accounts, and a public web portal. The current GSEC study scenario focuses on NIST CSF 2.0: leadership wants a common language for cyber risk governance across business units. Which response best addresses the security issue while preserving defensible operations?

स्पष्टीकरण:

NIST CSF 2.0 के कार्यों का उपयोग करें, जिसमें Govern शामिल है, क्योंकि यह निरीक्षण किए गए नियंत्रण के अंतर को एक व्यावहारिक बचावात्मक उपाय के साथ संबोधित करता है, जो सुरक्षा मुद्दे का समाधान करता है और संचालित संचालन को बनाए रखता है।

सबसे संभावित भ्रमितकर्ता (केवल पैकेट कैप्चर को शासन के ढांचे के रूप में उपयोग करें) गलत है क्योंकि तकनीकी सबूत अकेले व्यवसायिक इकाइयों के बीच साइबर जोखिम शासन को संरचित नहीं करते हैं; उम्मीदवार जो इसे चुनते हैं, वे निकटतम अवधारणा को विशिष्ट जोखिम के साथ भ्रमित करते हैं जो स्कीनरियो में दिखाया गया है।

Cryptography

A logistics provider has asked a new security administrator to prioritize practical changes that reduce risk without breaking warehouse operations. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

स्पष्टीकरण:

प्रक्रिया के सुरक्षा प्रशासक को एक नया सुरक्षा प्रशासक ने पूछा है कि वह जोखिम को कम करने के लिए व्यावहारिक परिवर्तनों को प्राथमिकता दे सकता है जो स्टोर ऑपरेशनों को तोड़े बिना। वर्तमान GSEC अध्ययन स्थिति पर ध्यान केंद्रित करती है: हैशिंग सुरक्षा की अखंडता: एक सॉफ़्टवेयर टीम चाहती है कि उपयोगकर्ता यह सत्यापित करें कि डाउनलोड के बाद इंस्टॉलर को संशोधित नहीं किया गया था। जो उत्तर सबसे अच्छी तरह से सुरक्षा मुद्दे को संबोधित करता है जबकि निर्विवाद ऑपरेशनों को बनाए रखता है?

प्रक्रिया के लिए एक क्रिप्टोग्राफिक हैश या डिजिटल हस्ताक्षर प्रकाशित करना सही है क्योंकि यह देखी गई नियंत्रण की खामोशी को एक व्यावहारिक रक्षात्मक उपाय के साथ संबोधित करता है। सबसे संभावित विकृति (AES से फ़ाइल नाम को एन्क्रिप्ट करें) गलत है क्योंकि फ़ाइल नाम का एन्क्रिप्शन फ़ाइल की अखंडता को साबित नहीं करता है; उम्मीदवार जो इसे चुनते हैं, वे निकटतम अवधारणा के साथ विशिष्ट जोखिम को भ्रमित कर रहे हैं जो स्थिति में दिखाया गया है।

Cloud, Virtualization, Containers, and AI Essentials

A regional hospital is preparing a 2025 cyber insurance renewal after merging two clinics. Legacy servers, cloud file sharing, and a small SOC are all in scope. The current GSEC study scenario focuses on Azure identity: a Microsoft Entra tenant has many guest users and no review of app consent grants. Which response best addresses the security issue while preserving defensible operations?

स्पष्टीकरण:

प्रश्न के अनुसार, क्षेत्रीय अस्पताल 2025 के साइबर बीमा नवीनीकरण की तैयारी कर रहा है जिसमें दो क्लिनिक का विलय शामिल है। विरासत वाले सर्वर, क्लाउड फाइल शेयरिंग और एक छोटा सीओसी सभी के भीतर हैं। वर्तमान जीईएसई स्टडी स्कीनरी में फोकस माइक्रोसॉफ्ट एंट्रा टेनेंट पर है: एक टेनेंट में कई मेहमान उपयोगकर्ता और ऐप कंसेंट ग्रांट्स की समीक्षा के बिना। जो उत्तर सबसे अच्छी तरह से सुरक्षा मुद्दे का समाधान करता है और बचाव के संचालन को बनाए रखता है वह निम्नलिखित है:

मेहमान एक्सेस, कंसेंट ग्रांट्स, कंडीशनल एक्सेस और प्राइविलेज्ड रोल असाइनमेंट की समीक्षा सही है क्योंकि यह देखी गई नियंत्रण की खामोशी के साथ एक व्यावहारिक बचाव उपाय को संबोधित करता है। सबसे संभावित भ्रमित करने वाला दूरस्थ (टेनेंट डिस्प्ले नाम बदलें) गलत है क्योंकि वास्तविक जोखिम को कम करने के लिए सौंदर्य संबंधी परिवर्तन नहीं होते हैं; जिन उम्मीदवारों ने इसे चुना है, वे निकटतम अवधारणा को विशिष्ट जोखिम के साथ भ्रमित कर रहे हैं जो स्कीनरी में दिखाया गया है।

Cryptography

A SaaS startup is moving from ad hoc administration to documented baseline controls, ticketed change approvals, and repeatable incident response. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

स्पष्टीकरण:

एक SaaS शुरुआती अपनी अनियमित प्रशासन से दस्तावेज़ी आधारित नियंत्रणों की ओर बढ़ रही है, टिकटेड परिवर्तन स्वीकृतियों और दुर्घटना प्रतिक्रियाओं की पुनरावृत्ति करने के लिए। वर्तमान GSEC अध्ययन पृष्ठभूमि में हैशिंग प्रामाणिकता पर केंद्रित है: एक सॉफ्टवेयर टीम को उपयोगकर्ताओं को यह सत्यापित करने की आवश्यकता है कि डाउनलोड के बाद इंस्टॉलर को किसी भी प्रकार से संशोधित नहीं किया गया था। जो उत्तर सुरक्षा मुद्दे को संबोधित करता है और सुरक्षित संचालन को बनाए रखने के लिए सबसे अच्छा है वह है:

प्रकाशित करना क्रिप्टोग्राफिक हैश या डिजिटल सिग्नेचर इंस्टॉलर को सही है क्योंकि यह देखी गई नियंत्रण की कमी का एक व्यावहारिक रक्षात्मक उपाय के साथ संबोधित करता है। सबसे संभावित भ्रमित करने वाला दूरस्थ (AES से फ़ाइल नाम को एन्क्रिप्ट करें) गलत है क्योंकि फ़ाइल नाम की एन्क्रिप्शन फ़ाइल की प्रामाणिकता को साबित नहीं करता है; जिन उम्मीदवारों ने इसे चुना है, वे निकटतम अवधारणा के साथ विशिष्ट जोखिम को उलझा रहे हैं जो पृष्ठभूमि में दिखाया गया है।

Vulnerability Management, Web Security, and Incident Response

A manufacturer with Windows 11 laptops, Ubuntu jump hosts, and a segmented OT lab is responding to audit findings from an external assessor. The current GSEC study scenario focuses on incident response first actions: EDR reports possible ransomware on one finance laptop while the user is still connected to file shares. Which response best addresses the security issue while preserving defensible operations?

स्पष्टीकरण:

एक निर्माता जिसके पास विंडोज़ 11 लैपटॉप, यूनिटी जंप होस्ट और एक विभाजित ओटी लैब है, एक बाहरी मूल्यांकनकर्ता से प्रतिक्रिया कर रहा है जो ऑडिट निष्कर्षों का जवाब दे रहा है। वर्तमान जीईएसईसी अध्ययन स्थिति में ध्यान केंद्रित है: घटना प्रतिक्रिया के पहले कार्यों पर: ईडीआर रिपोर्ट संभावित रैंसमवेयर को एक वित्तीय लैपटॉप पर, जबकि उपयोगकर्ता फ़ाइल शेयरों से जुड़ा हुआ है। जो प्रतिक्रिया सबसे अच्छी तरह से सुरक्षा मुद्दे का समाधान करती है जबकि बचाव के संचालन को बनाए रखती है?

मेजबान को बंद करें, प्रासंगिक सबूतों को संरक्षित करें, और घटना प्रतिक्रिया प्रक्रिया की शुरुआत करें यह सही है क्योंकि यह देखी गई नियंत्रण की खामोशी का एक व्यावहारिक बचाव उपाय के साथ संबोधित करता है। सबसे संभावित भ्रमितकर्ता (एक पूर्ण डिस्क वाइप चलाएं) गलत है क्योंकि वाइपिंग से स्कोप और सीमांत को समझने से पहले सबूतों को नष्ट कर सकता है; जिन उम्मीदवारों ने इसे चुना है, वे एक करीबी अवधारणा को विशिष्ट जोखिम के साथ जोड़ रहे हैं जो स्थिति में दिखाया गया है।

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

01Access Control & Password Management

विषय

  • Understand the fundamental theory of access control and the role of passwords in access control management.

सीखने के उद्देश्य

  • Understand the fundamental theory of access control and the role of passwords in access control management.

02Container and MacOS Security

विषय

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

सीखने के उद्देश्य

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

03Cryptography

विषय

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

सीखने के उद्देश्य

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

04Cryptography Application

विषय

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

सीखने के उद्देश्य

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

05Data Loss Prevention and Mobile Device Security

विषय

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

सीखने के उद्देश्य

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

06Defense in Depth

विषय

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

सीखने के उद्देश्य

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

07Defensible Network Architecture

विषय

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

सीखने के उद्देश्य

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

08Endpoint Security

विषय

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

सीखने के उद्देश्य

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

09Enforcing Windows Security Policy

विषय

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

सीखने के उद्देश्य

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

10Incident Handling & Response

विषय

  • Understand the concepts and processes associated with incident handling.

सीखने के उद्देश्य

  • Understand the concepts and processes associated with incident handling.

11Linux Fundamentals

विषय

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

सीखने के उद्देश्य

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

12Linux Security and Hardening

विषय

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

सीखने के उद्देश्य

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

13Log Management & SIEM

विषय

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

सीखने के उद्देश्य

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

14Malicious Code & Exploit Mitigation

विषय

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

सीखने के उद्देश्य

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

15Network Security Devices

विषय

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

सीखने के उद्देश्य

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

16Networking & Protocols

विषय

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

सीखने के उद्देश्य

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

17Security Frameworks and CIS Controls

विषय

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

सीखने के उद्देश्य

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

18Virtualization, Cloud Security, and AI Essentials

विषय

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

सीखने के उद्देश्य

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

19Vulnerability Scanning and Penetration Testing

विषय

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

सीखने के उद्देश्य

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

20Web Communication Security

विषय

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

सीखने के उद्देश्य

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

21Windows Access Controls

विषय

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

सीखने के उद्देश्य

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

22Windows as a Service

विषय

  • Understand how to manage updates for a network of Windows hosts.

सीखने के उद्देश्य

  • Understand how to manage updates for a network of Windows hosts.

23Windows Automation, Auditing, and Forensics

विषय

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

सीखने के उद्देश्य

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

24Windows Security Infrastructure

विषय

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

सीखने के उद्देश्य

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

25Windows Services and Microsoft Cloud

विषय

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

सीखने के उद्देश्य

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

26Wireless Network Security

विषय

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

सीखने के उद्देश्य

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

परीक्षा विवरण GSEC | $949 USD | 6 घंटे

परीक्षा कोड GSEC
विक्रेता GIAC
परीक्षा शुल्क $949 USD
उत्तीर्ण अंक 73
समय सीमा 6 घंटे
परीक्षा प्रश्न 180
प्रश्न प्रकार मल्टिपल चॉइस (100%)
पुनः परीक्षा नीति Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
परीक्षा प्रारूप Multiple Choice
ऑनलाइन निगरानी उपलब्ध

अक्सर पूछे जाने वाले प्रश्न

GSEC प्रमाणन के लिए सामान्य लक्षित दर्शक कौन हैं?

GSEC, CompTIA Security+ से कैसे भिन्न है?

GSEC परीक्षा के लिए अनुशंसित तैयारी का मार्ग क्या है?

परीक्षा का प्रारूप और अवधि क्या है?

GSEC प्रमाणन की वैधता कितनी है, और नवीनीकरण की आवश्यकताएँ क्या हैं?