GIAC · Security Essentials GSEC

GIAC Security Essentials GSEC Exam Practice Questions

279 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 279 questions in this pack

Question 1

Which of the following protocols is used by a host that knows its own MAC (Media Access Control) address to query a server for its own IP address?

  1. RARP
  2. ARP
  3. DNS
  4. RDNS
Show answer and explanation

Correct answer: A. RARP

RARP (Reverse Address Resolution Protocol) is specifically designed for a host to discover its own IP address when it knows its MAC address. A host with a known MAC address sends a RARP request to obtain the corresponding IP address from a RARP server.

Why the other options are wrong

  • B. ARP does the opposite, it resolves IP addresses to MAC addresses, not MAC to IP.
  • C. DNS resolves domain names to IP addresses, not MAC addresses to IP addresses.
  • D. RDNS (Reverse DNS) performs reverse lookups of IP addresses to domain names, not MAC to IP resolution.

Question 2

What is the motivation behind SYN/FIN scanning?

  1. The SYN/FIN combination is useful for signaling to certain Trojans.
  2. SYN/FIN packets are commonly used to launch denial of service attacks against BSD hosts.
  3. The crafted SYN/FIN packet sometimes gets past firewalls and filtering routers.
  4. A SYN/FIN packet is used in session hijacking to take over a session.
Show answer and explanation

Correct answer: C. The crafted SYN/FIN packet sometimes gets past firewalls and filtering routers.

firewalls and filtering routers. SYN/FIN scanning exploits the unusual combination of flags (SYN and FIN set simultaneously) to craft packets that may evade firewall rules and filtering routers. Many firewalls are configured to block standard connection attempts but may not properly handle or filter these non-standard packet combinations, allowing them to pass through.

Why the other options are wrong

  • A. SYN/FIN packets are not a standard signaling mechanism for Trojans.
  • B. While SYN floods are used in DoS attacks, SYN/FIN combinations are not a typical DoS vector, nor are they specifically targeted at BSD hosts.
  • D. Session hijacking uses sequence number prediction and packet injection, not SYN/FIN scanning techniques.

Question 3

There is not universal agreement on the names of the layers in the TCP/IP networking model.

Which of the following is one of the functions of the bottom layer which is sometimes called the Network Access or Link Layer?

  1. Provides end-to-end data delivery service for user applications
  2. Handles the routing of the data packets over the network
  3. Manages IP addressing and encryption for data packets
  4. Defines the procedures for interfacing with Ethernet devices
Show answer and explanation

Correct answer: D. Defines the procedures for interfacing with Ethernet devices

devices The Network Access or Link Layer (the bottom layer of the TCP/IP model) handles the physical transmission of data and defines how devices interface with network hardware. This includes procedures for interfacing with Ethernet devices, managing MAC addresses, and handling physical frame transmission.

Why the other options are wrong

  • A. This is a function of the Transport or Application layer, which provides end-to-end services for applications.
  • B. Routing is performed at the Internet layer, not the Link layer.
  • C. IP addressing is an Internet layer function, and encryption can occur at multiple layers but is not a primary Link layer responsibility.

See all 10 free questions Get the full pack, US$39

279 practice questions for GIAC Security Essentials (GSEC), with full explanations.

Every question comes with the correct answer and a clear explanation. Mapped to the current GSEC exam objectives.

  • 279 questions mapped to the GSEC exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The GSEC costs US$999 per attempt. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 279 questions

What makes the GSEC hard

The GSEC does not give much room for gaps. It is 106 questions in four hours, open book, with a 72% pass mark.

The exam covers a lot of ground, TCP/IP, cryptography, incident handling, access controls, Linux hardening, Windows security, cloud and virtualisation. It is broad by design, and most candidates who fail do not fail because they lack security knowledge; they fail because they did not realise how wide the question bank actually goes.

This pack has 279 practice questions covering the full range of what GIAC tests, so every domain can be pressure-tested, not just the comfortable ones.

About the exam

The GSEC validates practical, hands-on knowledge of information security beyond simple terminology. It is one of the most widely recognised security certifications in the industry and a common requirement for government and defence roles. It is aligned to the SANS Security Essentials course (network, endpoint and cloud) and mapped to DoD 8140/8570.

Exam topics

  • Networking fundamentals: TCP/IP, protocols, and network architecture
  • Cryptography: encryption, PKI, and secure communications
  • Access controls: authentication, authorisation, and identity management
  • Incident handling: detection, response, and recovery fundamentals
  • Linux security: hardening, permissions, and command-line defence
  • Windows security: Active Directory, Group Policy, and endpoint hardening
  • Defence in depth: layered security controls and risk management
  • Cloud and virtualisation security: securing modern infrastructure

106 questions, 4 hours, passing score 72%, open book, US$999 per attempt, valid 4 years, maps to DoD 8140/8570.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Security Essentials GSEC pack?

279 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.