giac gslc practice test

GIAC Security Leadership

Last exam update: Nov 18 ,2025
Page 1 out of 38. Viewing questions 1-15 out of 567

Question 1

Which of the following is used to describe the type of FTP access in which a user does not have
permissions to list the contents of directories, but can access the contents if he knows the path and
file name?

  • A. Secure FTP
  • B. Blind FTP
  • C. Passive FTP
  • D. Hidden FTP
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 2

Which system is designed to analyze, detect, and report on security-related events?

  • A. HIPS
  • B. NIPS
  • C. NIDS
  • D. HIDS
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Which of the following viruses is designed to prevent antivirus researchers from examining its code
by using various methods that make tracing and disassembling difficult?

  • A. Armored virus
  • B. Stealth virus
  • C. Multipartite virus
  • D. Polymorphic virus
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Which of the following provides security by implementing authentication and encryption on Wireless
LAN (WLAN)?

  • A. WEP
  • B. WAP
  • C. L2TP
  • D. IPSec
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

Which of the following are the examples of administrative controls?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Security policy
  • B. Auditing
  • C. Security awareness training
  • D. Data Backup
Mark Question:
Answer:

A, C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

John works as a Programmer for We-are-secure Inc. On one of his routine visits to the company, he
noted down the passwords of the employees while they were typing them on their computer
screens.
Which of the following social engineering attacks did he just perform?

  • A. Shoulder surfing
  • B. Important user posing
  • C. Dumpster diving
  • D. Authorization by third party
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Which of the following encryption algorithms is applied in the PGP encryption system?

  • A. TDE
  • B. Triple DES
  • C. Blowfish
  • D. IDEA
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

Rick, the Network Administrator of the Fimbry Hardware Inc., wants to design the initial test model
for Internet Access. He wants to fulfill the following goals:
No external traffic should be allowed into the network.
Administrators should be able to restrict the websites which can be accessed by the internal users.
Which of the following technologies should he use to accomplish the above goals? (Click the Exhibit
button on the toolbar to see the case study.)

  • A. Internet Connection Sharing (ICS)
  • B. Network Address Translator (NAT)
  • C. Firewall
  • D. Proxy Server
  • E. Routing and Remote Access Service (RRAS)
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%
Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 9

You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008
network environment. The network is configured as a Windows Active Directory-based single forest
single domain network. The domain functional level is set to Windows Server 2003. You have
configured an Active Directory-integrated DNS zone on the network. A new security policy dictates
that each incoming DNS query should be recorded. Which of the following steps will you take to
implement the new security policy?

  • A. Create a GPO. Configure Audit Object Access. Attach the GPO to the domain.
  • B. Do nothing, each incoming DNS queries is recorded by default in DNS.LOG file.
  • C. Enable debug logging on the DNS server.
  • D. Create a new OU. Move the DNS server account to the OU. Create a GPO. Configure Audit Logon events. Attach the GPO to the OU.
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which of the following are the goals of risk management?
Each correct answer represents a complete solution. Choose three.

  • A. Identifying the risk
  • B. Finding an economic balance between the impact of the risk and the cost of the countermeasure
  • C. Identifying the accused
  • D. Assessing the impact of potential threats
Mark Question:
Answer:

A, B, D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

The promiscuous mode is a configuration of a network card that makes the card pass all traffic it
receives to the central processing unit rather than just packets addressed to it. Which of the
following tools works by placing the host system network card into the promiscuous mode?

  • A. Sniffer
  • B. THC-Scan
  • C. NetStumbler
  • D. Snort
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

Janet is the project manager of the NHQ Project for her company. Janet is nearly done leading the
project and there have been no cost or schedule overruns in the development of the new software
for her company. The project team has been completing their work on time and there is still $75,000
left in the project budget. Janet decides to have the project team implement some extra features to
the project scope to use all of the $75,000 in the budget even though the customer didn't specifically
ask for the added features. This scenario is an example of which one of the following?

  • A. Scope creep
  • B. Gold plating
  • C. Change management
  • D. Value added change
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

You are responsible for security at a company that uses a lot of Web applications. You are most
concerned about flaws in those applications allowing some attacker to get into your network. What
method would be best for finding such flaws?

  • A. Automated penetration testing
  • B. Code review
  • C. Manual penetration testing
  • D. Vulnerability scanning
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

Fill in the blank with the appropriate word.
A_______ is a computer system on the Internet that is expressly set up to attract and trap people
who attempt to penetrate other people's computer systems.

Mark Question:
Answer:

honeypot

User Votes:
Discussions
vote your answer:
0 / 1000

Question 15

Which of the following protocols is used as a transport protocol for Internet dial-up connections?

  • A. SMTP
  • B. SNMP
  • C. DHCP
  • D. PPP
Mark Question:
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2