Exam : GSECTitle : GIAC Security EssentialsCertificationVendor : GIACVersion : V12.95IT Certification Guaranteed, The Easy Way!1SAMPLE QUESTIONSNO.1 What is the function of the TTL (Time to Live) field in IPv4 and the Hop Limit field in IPv6 In anIP Packet header?(A). These fields are decremented each time a packet is retransmitted to minimize the possibility ofrouting loops.(B). These fields are
...[Show More]
Exam : GSEC
Title : GIAC Security Essentials
Certification
Vendor : GIAC
Version : V12.95
IT Certification Guaranteed, The Easy Way!
1
SAMPLE QUESTIONS
NO.1 What is the function of the TTL (Time to Live) field in IPv4 and the Hop Limit field in IPv6 In an
IP Packet header?
(A). These fields are decremented each time a packet is retransmitted to minimize the possibility of
routing loops.
(B). These fields are initialized to an initial value to prevent packet fragmentation and fragmentation
attacks.
(C). These fields are recalculated based on the required time for a packet to arrive at its destination.
(D). These fields are incremented each time a packet is transmitted to indicate the number of routers
that an IP packet has traversed.
Answer: A
NO.2 Which of the following protocols implements VPN using IPSec?
(A). SLIP
(B). PPP
(C). L2TP
(D). PPTP
Answer: C
NO.3 What is the main problem with relying solely on firewalls to protect your company's sensitive
data?
(A). Their value is limited unless a full-featured Intrusion Detection System is used.
(B). Their value is limited because they cannot be changed once they are configured.
(C). Their value is limited because operating systems are now automatically patched.
(D). Their value is limited because they can be bypassed by technical and non-technical means.
Answer: D
NO.4 You work as a Network Administrator for NetTech Inc. The company wants to encrypt its emails. Which of the following will you use to accomplish this?
(A). PPTP
(B). IPSec
(C). PGP
(D). NTFS
Answer: C
NO.5 Against policy, employees have installed Peer-to-Peer applications on their workstations and
they are using them over TCP port 80 to download files via the company network from other Peer-toPeer users on the Internet. Which of the following describes this threat?
(A). Firewall subversion
(B). Backdoor installation
(C). Malicious software infection
(D). Phishing attempt
Answer: A
NO.6 Why would someone use port 80 for deployment of unauthorized services?
(A). Google will detect the service listing on port 80 and post a link, so that people all over the world
will surf to the rogue service.
IT Certification Guaranteed, The Easy Way!
2
(B). If someone were to randomly browse to the rogue port 80 service they could be compromised.
(C). This is a technique commonly used to perform a denial of service on the local web server.
(D). HTTP traffic is usually allowed outbound to port 80 through the firewall in most environments.
Answer: D
NO.7 When using Pretty Good Privacy (PGP) to digitally sign a message, the signature is created in a
two-step process. First, the message to be signed is submitted to PGP's cryptographic hash algorithm.
What is one of the hash algorithms used by PGP for this process?
(A). Blowfish
(B). DES
(C). SHA-l
(D). Cast
Answer: C
NO.8 Which of the following types of computers is used for attracting potential intruders?
(A). Files pot
(B). Honey pot
(C). Data pot
(D). Bastion host
Answer: B
NO.9 Which command would allow an administrator to determine if a RPM package was already
installed?
(A). rpm -s
(B). rpm -q
(C). rpm -a
(D). rpm -t
Answer: B
NO.10 When a host on a remote network performs a DNS lookup of www.google.com, which of the
following is likely to provide an Authoritative reply?
Answer: A
NO.11 Which of the following protocols describes the operation of security In H.323?
(A). H.239
(B). H.245
(C). H.235
(D). H.225
Answer: C
NO.12 There are three key factors in selecting a biometric mechanism. What are they?
(A). Reliability, encryption strength, and cost
IT Certification Guaranteed, The Easy Way!
3
(B). Encryption strength, authorization method, and cost
(C). Reliability, user acceptance, and cost
(D). User acceptance, encryption strength, and cost
Answer: C
NO.13 How is a Distributed Denial of Service (DDOS) attack distinguished from a regular DOS attack?
(A). DDOS attacks are perpetrated by many distributed hosts.
(B). DDOS affects many distributed targets.
(C). Regular DOS focuses on a single router.
(D). DDOS affects the entire Internet.
Answer: A
NO.14 Which of the following is NOT typically used to mitigate the war dialing threat?
(A). Setting up monitored modems on special phone numbers
(B). Setting modems to auto-answer mode
(C). Proactively scanning your own phone numbers
(D). Monitoring call logs at the switch
Answer: B
NO.15 What are the two actions the receiver of a PGP email message can perform that allows
establishment of trust between sender and receiver?
(A). Decode the message by decrypting the asymmetric key with his private key, then using the
asymmetric key to decrypt the message.
(B). Decode the message by decrypting the symmetric key with his private key, then using the
symmetric key to decrypt the message.
(C). Decode the message by decrypting the symmetric key with his public key, then using the
symmetric key to decrypt the message.
(D). Decrypt the message by encrypting the digital signature with his private key, then using the
digital signature to decrypt the message.
Answer: A
NO.16 You are reviewing a packet capture file from your network intrusion detection system. In the
packet stream, you come across a long series of "no operation" (NOP) commands. In addition to the
NOP commands, there appears to be a malicious payload. Of the following, which is the most
appropriate preventative measure for this type of attack?
(A). Limits on the number of failed logins
(B). Boundary checks on program inputs
(C). Controls against time of check/time of use attacks
(D). Restrictions on file permissions
Answer: C
NO.17 When discussing access controls, which of the following terms describes the process of
determining the activities or functions that an Individual is permitted to perform?
(A). Authentication
(B). Identification
(C). Authorization
IT Certification Guaranteed, The Easy Way!
4
(D). Validation
Answer: C
NO.18 Which of the following is an advantage of a Host Intrusion Detection System (HIDS) versus a
Network Intrusion Detection System (NIDS)?
(A). Ability to detect malicious traffic after it has been decrypted by the host
(B). Ability to decrypt network traffic
(C). Ability to listen to network traffic at the perimeter
(D). Ability to detect malicious traffic before it has been decrypted
Answer: A
NO.19 You are examining a packet capture session in Wire shark and see the packet shown in the
accompanying image. Based on what you see, what is the appropriate protection against this type of
attempted attack?
(A). Block DNS traffic across the router
(B). Disable forwarding of unsolicited TCP requests
(C). Disable IP-directed broadcast requests
(D). Block UDP packets at the firewall
Answer: C
NO.20 Which aspect of UNIX systems was process accounting originally developed for?
(A). Data warehouse
(B). Time sharing
(C). Process tracking
(D). Real time
Answer: C
NO.21 Which of the following elements is the most important requirement to ensuring the success
of a business continuity plan?
(A). Disaster Recover Plans
(B). Anticipating all relevant threats
(C). Executive buy-in
(D). Clearly defining roles and responsibilities
(E). Training
Answer: C
NO.22 Which of the following commands is used to change file access permissions in Linux?
(A). chgrp
(B). chperm
(C). chmod
(D). chown
Answer: C
IT Certification Guaranteed, The Easy Way!
5
NO.23 Which of the following protocols provides maintenance and error reporting function?
(A). UDP
(B). ICMP
(C). PPP
(D). IGMP
Answer: B
NO.24 What is the discipline of establishing a known baseline and managing that condition known
as?
(A). Condition deployment
(B). Observation discipline
(C). Security establishment
(D). Configuration management
Answer: C
NO.25 What defensive measure could have been taken that would have protected the
confidentiality of files that were divulged by systems that were compromised by malware?
(A). Ingress filtering at the host level
(B). Monitoring for abnormal traffic flow
(C). Installing file integrity monitoring software
(D). Encrypting the files locally when not in use
Answer: D
NO.26 Which of the following languages enable programmers to store cookies on client computers?
Each correct answer represents a complete solution. Choose two.
(A). DHTML
(B). Perl
(C). HTML
(D). JavaScript
Answer: B,D
NO.27 The previous system administrator at your company used to rely heavily on email lists, such
as vendor lists and Bug Traq to get information about updates and patches. While a useful means of
acquiring data, this requires time and effort to read through. In an effort to speed things up, you
decide to switch to completely automated updates and patching. You set up your systems to
automatically patch your production servers using a cron job and a scripted apt-get upgrade
command. Of the following reasons, which explains why you may want to avoid this plan?
(A). The apt-get upgrade command doesn't work with the cron command because of incompatibility
(B). Relying on vendor and 3rd party email lists enables updates via email, for even faster patching
(C). Automated patching of production servers without prior testing may result in unexpected
behavior or failures
(D). The command apt-get upgrade is incorrect, you need to run the apt-get update command
Answer: D
NO.28 Which of the following are network connectivity devices?
Each correct answer represents a complete solution. Choose all that apply.
IT Certification Guaranteed, The Easy Way!
6
(A). Network analyzer
(B). Bridge
(C). Brouter
(D). Firewall
(E). Repeater
(F). Hub
Answer: B,C,E,F
NO.29 You work as an Administrator for McRoberts Inc. The company has a Linux-based network.
You are logged in as a non-root user on your client computer. You want to delete all files from the
/garbage directory. You want that the command you will use should prompt for the root user
password. Which of the following commands will you use to accomplish the task?
(A). rm -rf /garbage*
(B). del /garbage/*.*
(C). rm -rf /garbage* /SU
(D). su -c "RM -rf /garbage*"
Answer: D
NO.30 A sensor that uses a light beam and a detecting plate to alarm if the light beam is obstructed
is most commonly used to identify which of the following threats?
Answer: B
NO.31 What is the maximum number of connections a normal Bluetooth device can handle at one
time?
(A). 2
(B). 4
(C). 1
(D). 8
(E). 7
Answer: E
NO.32 When you log into your Windows desktop what information does your Security Access Token
(SAT) contain?
(A). The Security ID numbers (SIDs) of all the groups to which you belong
(B). A list of cached authentications
(C). A list of your domain privileges
(D). The Security ID numbers (SIDs) of all authenticated local users
Answer: C
NO.33 Which of the following protocols is used by a host that knows its own MAC (Media Access
Control) address to query a server for its own IP address?
IT Certification Guaranteed, The Easy Way!
7
(A). RARP
(B). ARP
(C). DNS
(D). RDNS
Answer: A
NO.34 Which of the following protocols allows an e-mail client to access and manipulate a remote email file without downloading it to the local computer?
(A). IMAP
(B). SNMP
(C). POP3
(D). SMTP
Answer: A
NO.35 Which of the following is a private, RFC 1918 compliant IP address that would be assigned to
a DHCP scope on a private LAN?
(A). 127.0.0.100
(B). 169.254.1.50
(C). 10.254.1.50
(D). 172.35.1.100
Answer: C
NO.36 Which of the following is a standard Unix command that would most likely be used to copy
raw file system data for later forensic analysis?
(A). dd
(B). backup
(C). cp
(D). gzip
Answer: A
NO.37 You are going to upgrade your hard disk's file system from FAT to NTFS. What are the major
advantages of the NTFS file system over FAT16 and FAT32 file systems?
Each correct answer represents a complete solution. Choose all that apply.
(A). NTFS gives better file security than FAT16 and FAT32.
(B). Automatic backup.
(C). NTFS file system supports for larger hard disks.
(D). NTFS give improved disk compression than FAT16 and FAT32.
Answer: A,C,D
NO.38 Which Windows event log would you look in if you wanted information about whether or not
a specific diver was running at start up?
(A). Application
(B). System
(C). Startup
(D). Security
Answer: B
IT Certification Guaranteed, The Easy Way!
8
NO.39 You work as a Network Administrator for Tech Perfect Inc. The company has a Linux-based
network. You want to kill a process running on a Linux server. Which of the following commands will
you use to know the process identification number (PID) of the process?
(A). killall
(B). ps
(C). getpid
(D). kill
Answer: B
NO.40 During which of the following steps is the public/private key-pair generated for Public Key
Infrastructure (PKI)?
Answer: B
NO.41 Which Linux file lists every process that starts at boot time?
(A). inetd
(B). netsrv
(C). initd
(D). inittab
Answer: D
NO.42 When Net Stumbler is initially launched, it sends wireless frames to which of the following
addresses?
(A). Broadcast address
(B). Default gateway address
(C). Subnet address
(D). Network address
Answer: A
NO.43 What is the key difference between Electronic Codebook mode and other block cipher modes
like Cipher Block Chaining, Cipher-Feedback and Output-Feedback?
(A). Plaintext patterns are concealed by XO Ring with previous cipher text block but input to the block
cipher is not randomized.
(B). Plaintext patterns are concealed and input to the block cipher is randomized by XO Ring with
previous cipher text block.
(C). Plaintext patterns encrypted with the same key will always generate the same Cipher text patter
n
(D). Plaintext patterns are not concealed but input to the block cipher is randomized by XO Ring with
previous cipher text block.
Answer: C
NO.44 Which of the following terms refers to the process in which headers and trailers are added
IT Certification Guaranteed, The Easy Way!
9
around user data?
(A). Encapsulation
(B). Authentication
(C). Authorization
(D). Encryption
Answer: A
NO.45 When a packet leaving the network undergoes Network Address Translation (NAT), which of
the following is changed?
(A). TCP Sequence Number
(B). Source address
(C). Destination port
(D). Destination address
Answer: B
NO.46 Which of the following TCP dump output lines indicates the first step in the TCP 3-way
handshake?
(A). 07:09:43.368615 download.net 39904 > ftp.com.21: S 733381829:733381829(0) win 8760 <mss
1460> (DF)
(B). 07:09:43.370302 ftp.com.21 > download.net.39904: S 1192930639:1192930639(0} ack
733381830 win 1024 <mss 1460> (DF)
(C). 09:09:22.346383 ftp.com.21 > download.net.39904: , rst 1 win 2440(DF)
(D). 07:09:43.370355 download.net.39904 > ftp.com.21: , ack 1 win 8760 (DF)
Answer: A
NO.47 What is the term for a game in which for every win there must be an equivalent loss?
(A). Asymmetric
(B). Untenable
(C). Zero-sum
(D). Gain-oriented
Answer: C
NO.48 Which of the following is used to allow or deny access to network resources?
(A). Spoofing
(B). ACL
(C). System hardening
(D). NFS
Answer: B
NO.49 You are responsible for a Microsoft based network. Your servers are all clustered. Which of
the following are the likely reasons for the clustering?
Each correct answer represents a complete solution. Choose two.
(A). Reduce power consumption
(B). Ease of maintenance
(C). Load balancing
(D). Failover
IT Certification Guaranteed, The Easy Way!
10
Answer: C,D
NO.50 In a /24 subnet, which of the following is a valid broadcast address?
Answer: D
[Show Less]