Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GIAC Critical Controls Certification GCCC Exam Questions

Page: 1 / 10 Total 93 questions

Want more questions? Get Premium Access.

Question 1

An organization has implemented a policy to detect and remove malicious software from its network. Which of the following actions is focused on correcting rather than preventing attack?

Correct Answer: B. Using Network access control to disable communication by hosts with viruses

Question 2

John a network administrator at Northeast High School. Faculty have been complaining that although they can detect and authenticate to the faculty wireless network, they are unable to connect. While troubleshooting, John discovers that the wireless network server is out of DHCP addresses due to a large number of unauthorized student devices connecting to the network. Which course of action would be an effective temporary stopgap to secure the network until a permanent solution can be found?

Correct Answer: C. Change the password immediately

Question 3

Beta corporation is doing a core evaluation of its centralized logging capabilities. The security staff suspects that the central server has several log files over the past few weeks that have had their contents changed. Given this concern, and the need to keep archived logs for log correction applications, what is the most appropriate next steps?

Correct Answer: B. Store the files read-only and keep hashes of the logs separately.

Question 4

An organization has implemented a control for Controlled Use of Administrative Privileges. They are collecting audit data for each login, logout, and location for the root account of their MySQL server, but they are unable to attribute each of these logins to a specific user. What action can they take to rectify this?

Correct Answer: C. Force user accounts to use 'sudo' f or privileged use.

Question 5

As part of an effort to implement a control on E-mail and Web Protections, an organization is monitoring their webserver traffic. Which event should they receive an alert on?

Correct Answer: C. The website does not respond to a SYN packet for 30 minutes

Question 6

An organization is implementing a control within the Application Software Security CIS Control. How can they best protect against injection attacks against their custom web application and database applications?

Correct Answer: B. Filter input to only allow safe characters and strings

Question 7

Allied services have recently purchased NAC devices to detect and prevent non-company owned devices from attaching to their internal wired and wireless network. Corporate devices will be automatically added to the approved device list by querying Active Directory for domain devices. Non-approved devices will be placed on a protected VLAN with no network access. The NAC also offers a web portal that can be integrated with Active Directory to allow for employee device registration which will not be utilized in this deployment. Which of the following recommendations would make NAC installation more secure?

Correct Answer: C. Disable the web portal device registration service

Question 8

Which of the following will decrease the likelihood of eavesdropping on a wireless network?

Correct Answer: C. Using EAP/TLS authentication and WPA2 with AES encryption

Question 9

An organization is implementing a control for the Limitation and Control of Network Ports, Protocols, and Services CIS Control. Which action should they take when they discover that an application running on a web server is no longer needed?

Correct Answer: A. Uninstall the application providing the service

Question 10

If an attacker wanted to dump hashes or run wmic commands on a target machine, which of the following tools would he use?

Correct Answer: C. Metasploit