GIAC Security Essentials (GSEC) Practice Test

189 questions available

Build your confidence for GIAC Security Essentials (GSEC). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
180 Exam questions
6 hours Time Limit
Your practice
189 Practice questions
3 hours 9 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 73 Published passing score for this certification.
Explore exam topics Official objectives from GIAC
GIAC189 practice questions
Blueprint verifiedChecked against GIAC official objectivesMetadata verified 2026-06-11How we verify

Exam overview and details

The GIAC Security Essentials (GSEC) certification is a globally recognized, vendor-neutral credential that validates a practitioner's foundational knowledge and hands-on skills in information security. Administered by the Global Information Assurance Certification (GIAC) organization, the GSEC exam assesses core competencies across multiple security domains, ensuring certified professionals possess the practical abilities required to secure modern IT environments. Earning the GSEC demonstrates to employers a verified understanding of essential security concepts, including network defense, cryptography, access controls, and hardening of Windows and Linux systems. It is often a prerequisite for intermediate and advanced security roles, serving as a critical benchmark for hiring managers and a cornerstone for building a comprehensive security career. The certification is aligned with the SANS Institute's training, emphasizing real-world application over theoretical knowledge, which makes GSEC holders immediately valuable in operational security teams.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Security Frameworks and CIS Controls

A university IT team is standardizing controls across dorm networks, research labs, Microsoft 365, AWS accounts, and a public web portal. The current GSEC study scenario focuses on NIST CSF 2.0: leadership wants a common language for cyber risk governance across business units. Which response best addresses the security issue while preserving defensible operations?

Cryptography

A logistics provider has asked a new security administrator to prioritize practical changes that reduce risk without breaking warehouse operations. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

Cloud, Virtualization, Containers, and AI Essentials

A regional hospital is preparing a 2025 cyber insurance renewal after merging two clinics. Legacy servers, cloud file sharing, and a small SOC are all in scope. The current GSEC study scenario focuses on Azure identity: a Microsoft Entra tenant has many guest users and no review of app consent grants. Which response best addresses the security issue while preserving defensible operations?

Cryptography

A SaaS startup is moving from ad hoc administration to documented baseline controls, ticketed change approvals, and repeatable incident response. The current GSEC study scenario focuses on hashing integrity: a software team wants users to verify that an installer was not modified after download. Which response best addresses the security issue while preserving defensible operations?

Vulnerability Management, Web Security, and Incident Response

A manufacturer with Windows 11 laptops, Ubuntu jump hosts, and a segmented OT lab is responding to audit findings from an external assessor. The current GSEC study scenario focuses on incident response first actions: EDR reports possible ransomware on one finance laptop while the user is still connected to file shares. Which response best addresses the security issue while preserving defensible operations?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

In the competitive cybersecurity landscape, the GSEC certification provides tangible proof of your foundational technical skills and commitment to the profession. It is frequently cited in job requirements for Security Analysts, Administrators, and Engineers, directly enhancing your marketability and earning potential. Holding a GSEC signals to industry peers and employers that you have met a rigorous, performance-based standard set by one of the most respected bodies in cybersecurity. This recognition opens doors to advanced roles and specialized certifications, establishing a credible and respected foundation for long-term career progression in information security.

What this exam covers

01Access Control & Password Management

Topics

  • Understand the fundamental theory of access control and the role of passwords in access control management.

Learning objectives

  • Understand the fundamental theory of access control and the role of passwords in access control management.

02Container and MacOS Security

Topics

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

Learning objectives

  • Demonstrate an understanding of how to secure containers and understand security features provided in MacOS.

03Cryptography

Topics

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

Learning objectives

  • Have a basic understanding of the concepts of cryptography, including the major types of cryptosystems, the mathematical concepts that contribute to cryptography and identify commonly used symmetric, asymmetric, and hashing cryptosystems.

04Cryptography Application

Topics

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

Learning objectives

  • Have a high-level understanding of the use, functionality, and operation of VPNs, GPG, and PKI.

05Data Loss Prevention and Mobile Device Security

Topics

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

Learning objectives

  • Understand the risks and impacts of data loss, how to prevent it, and the security considerations of mobile devices.

06Defense in Depth

Topics

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

Learning objectives

  • Understand what defense in depth is, identify the key areas of security, and demonstrate the different strategies for implementing effective security within an organization.

07Defensible Network Architecture

Topics

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

Learning objectives

  • Demonstrate how to architect a network to be monitored and controlled to resist intrusion.

08Endpoint Security

Topics

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

Learning objectives

  • Demonstrate a basic understanding of the function and uses of endpoint security devices, such as endpoint firewalls, HIDS, and HIPS.

09Enforcing Windows Security Policy

Topics

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

Learning objectives

  • Have a high-level understanding of the features of Group Policy and working with INF security templates.

10Incident Handling & Response

Topics

  • Understand the concepts and processes associated with incident handling.

Learning objectives

  • Understand the concepts and processes associated with incident handling.

11Linux Fundamentals

Topics

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

Learning objectives

  • Demonstrate an understanding of the Linux operating system structure, vulnerabilities, and permissions.

12Linux Security and Hardening

Topics

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

Learning objectives

  • Demonstrate an understanding of gaining visibility into a Linux system to be able to secure, audit, and harden the system.

13Log Management & SIEM

Topics

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

Learning objectives

  • Demonstrate a high-level understanding of logging importance, configuration, and SIEM assisted analysis.

14Malicious Code & Exploit Mitigation

Topics

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

Learning objectives

  • Understand important attack methods and basic defensive strategies to mitigate malicious software threats and exploitations.

15Network Security Devices

Topics

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

Learning objectives

  • Demonstrate a basic understanding of the function and uses of network security devices, such as firewalls, NIDS, and NIPS.

16Networking & Protocols

Topics

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

Learning objectives

  • Demonstrate an understanding of the properties and functions of network protocols and network protocol stacks.

17Security Frameworks and CIS Controls

Topics

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

Learning objectives

  • Understand the purpose, implementation, and background of the CIS Critical Controls, NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

18Virtualization, Cloud Security, and AI Essentials

Topics

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

Learning objectives

  • Have a basic understanding of concepts of virtualization, cloud architectures, and AI fundamentals.

19Vulnerability Scanning and Penetration Testing

Topics

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

Learning objectives

  • Demonstrate an understanding of the concepts and relationship behind reconnaissance, resource protection, risks, threats, and vulnerabilities including the creation of network maps and penetration testing techniques.

20Web Communication Security

Topics

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

Learning objectives

  • Demonstrate an understanding of web application security and common vulnerabilities including cookies, SSL, and access control.

21Windows Access Controls

Topics

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

Learning objectives

  • Understand how permissions are applied in the Windows NT File System, Shared Folders, Printers, Registry Keys, and Active Directory, and how Privileges are applied.

22Windows as a Service

Topics

  • Understand how to manage updates for a network of Windows hosts.

Learning objectives

  • Understand how to manage updates for a network of Windows hosts.

23Windows Automation, Auditing, and Forensics

Topics

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

Learning objectives

  • Understand the techniques and technologies used to audit Windows hosts and simple PowerShell scripting.

24Windows Security Infrastructure

Topics

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

Learning objectives

  • Identify the differences between types of Windows OSes and how Windows manages groups and accounts, locally and with Active Directory and Group Policy.

25Windows Services and Microsoft Cloud

Topics

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

Learning objectives

  • Understand how to take basic measures in securing Windows network services such as IPsec, IIS, and Remote Desktop Services and Microsoft Azure security features.

26Wireless Network Security

Topics

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

Learning objectives

  • Have a basic understanding of the configuration and risks of wireless networks and how to secure them.

Exam Details GSEC | $949 USD | 6 hours

Exam Code GSEC
Vendor GIAC
Exam Cost $949 USD
Passing Score 73
Time Limit 6 hours
Exam questions 180
Question Types Multiple choice (100%)
Retake Policy Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Exam Format Multiple Choice
Online Proctoring Available

Frequently Asked Questions

What is the typical target audience for the GSEC certification?

How does the GSEC differ from CompTIA Security+?

What is the recommended preparation path for the GSEC exam?

What is the exam format and duration?

How long is the GSEC certification valid, and what are the renewal requirements?