[2021] Pass GIAC GCCC Test Practice Test Questions Exam Dumps
Verified GCCC dumps Q&As - GCCC dumps with Correct Answers
GIAC GCCC Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
NEW QUESTION 50
An auditor is focusing on potential vulnerabilities. Which of the following should cause an alert?
- A. Fully patched guest machine that is not in the asset inventory
- B. Workstation on which a domain admin has never logged in
- C. Server that has zero browser plug-ins
- D. Windows host with an uptime of 382 days
Answer: D
NEW QUESTION 51
An organization wants to test its procedure for data recovery. Which of the following will be most effective?
- A. Verifying there are no errors in the backup server logs
- B. Verifying that backup process is running when it should
- C. Verifying a file can be recovered from backup media
- D. Verifying that network backups can't be read in transit
Answer: C
NEW QUESTION 52
Acme Corporation is doing a core evaluation of its centralized logging capabilities. Which of the following scenarios indicates a failure in more than one CIS Control?
- A. The loghost is missing logs from 3 servers in the inventory
- B. The loghost time is out-of-sync with an external host
- C. The loghost is receiving logs from hosts with different timezone values
- D. The loghost is receiving out-of-sync logs from undocumented servers
Answer: D
NEW QUESTION 53
According to attack lifecycle models, what is the attacker's first step in compromising an organization?
- A. Reconnaissance
- B. Privilege Escalation
- C. Initial Compromise
- D. Exploitation
Answer: A
NEW QUESTION 54
Based on the data shown below.
Which wireless access point has the manufacturer default settings still in place?
- A. Linksys
- B. Hhonors
- C. Starbucks
- D. Interwebz
Answer: A
NEW QUESTION 55
Which of the options below will do the most to reduce an organization's attack surface on the internet?
- A. Ensure that rotation of duties is used with employees in order to compartmentalize the most important tasks
- B. Deploy antivirus software on internet-facing hosts, and ensure that the signatures are updated regularly
- C. Deploy an access control list on the perimeter router and limit inbound ICMP messages to echo requests only
- D. Ensure only necessary services are running on Internet-facing hosts, and that they are hardened according to best practices
Answer: D
NEW QUESTION 56
A security incident investigation identified the following modified version of a legitimate system file on a compromised client:
C:\Windows\System32\winxml.dll Addition Jan. 16, 2014 4:53:11 PM
The infection vector was determined to be a vulnerable browser plug-in installed by the user. Which of the organization's CIS Controls failed?
- A. Application Software Security
- B. Maintenance, Monitoring, and Analysis of Audit Logs
- C. Inventory and Control of Hardware Assets
- D. Inventory and Control of Software Assets
Answer: D
NEW QUESTION 57
Which of the following is necessary to automate a control for Inventory and Control of Hardware Assets?
- A. An up-to-date hardening guide
- B. An inventory of unauthorized assets
- C. A method of device scanning
- D. A centralized time server
Answer: C
NEW QUESTION 58
Which of the following actions produced the output seen below?
- A. An access rule was removed from firewallrules.txt
- B. An access rule was added to firewallrules2.txt
- C. An access rule was removed from firewallrules2.txt
- D. An access rule was added to firewallrules.txt
Answer: B
NEW QUESTION 59
What is a recommended defense for the CIS Control for Application Software Security?
- A. Run a dedicated vulnerability scanner against backend databases
- B. Display system error messages for only non-kernel related events
- C. Limit access to the web application production environment to just the developers
- D. Keep debugging code in production web applications for quick troubleshooting
Answer: A
NEW QUESTION 60
An attacker is able to successfully access a web application as root using ' or 1 = 1 . as the password. The successful access indicates a failure of what process?
- A. Input Validation
- B. URL Encoding
- C. Account Management
- D. Output Sanitization
Answer: A
NEW QUESTION 61
John is implementing a commercial backup solution for his organization. Which of the following steps should be on the configuration checklist?
- A. Develop a unique encryption scheme
- B. Disable software-level encryption to increase speed of transfer
- C. Enable encryption if it 's not enabled by default
Answer: C
NEW QUESTION 62
An organization has implemented a control for penetration testing and red team exercises conducted on their network. They have compiled metrics showing the success of the penetration testing (Penetration Tests), as well as the number of actual adversary attacks they have sustained (External Attacks). Assess the metrics below and determine the appropriate interpretation with respect to this control.
- A. The blue team is adequately protecting the network
- B. The red team is improving their capability to measure network security
- C. The methods the red team is using are not effectively testing the network
- D. There are too many internal penetration tests being conducted
Answer: C
NEW QUESTION 63
An analyst investigated unused organizational accounts. The investigation found that:
-10% of accounts still have their initial login password, indicating they were never used
-10% of accounts have not been used in over six months
Which change in policy would mitigate the security risk associated with both findings?
- A. Accounts without login activity for 15 days are automatically locked
- B. Accounts must have passwords of at least 8 characters, with one number or symbol
- C. Users are required to change their password at the next login after three months
Answer: A
NEW QUESTION 64
Acme Corporation performed an investigation of its centralized logging capabilities. It found that the central server is missing several types of logs from three servers in Acme's inventory. Given these findings, what is the most appropriate next step?
- A. Restart or reinstall the logging service on each of the problem servers
- B. Perform analysis to identify the source of the logging problems
- C. Define processes to manually review logs for the problem servers
- D. Document the missing logs in the core evaluation report as a minor issue
Answer: B
NEW QUESTION 65
An organization has installed a firewall for Boundary Defense. It allows only outbound traffic from internal workstations for web and SSH, allows connections from the internet to the DMZ, and allows guest wireless access to the internet only. How can an auditor validate these rules?
- A. Try to send email from a wireless guest account
- B. Try to access the internal network from the wireless router
- C. Check for packets going from the Internet to the Web server
- D. Check for packages going from the web server to the user workstations
Answer: B
NEW QUESTION 66
An organization is implementing a control within the Application Software Security CIS Control. How can they best protect against injection attacks against their custom web application and database applications?
- A. Ensure the web application server logs are going to a central log host
- B. Filter input to only allow safe characters and strings
- C. Configure the web server to use Unicode characters only
- D. Check user input against a list of reserved database terms
Answer: B
NEW QUESTION 67
......
GCCC certification guide Q&A from Training Expert DumpsValid: https://www.dumpsvalid.com/GCCC-still-valid-exam.html
The Best Cyber Security Study Guide for the GCCC Exam: https://drive.google.com/open?id=1IvaFfL4lBpIm7GJnoEuWh9WOZzyZXPVD