GCCC Practice Exam and Study Guides - Verified By DumpsTests Updated 95 Questions [Q30-Q54]

Share

GCCC Practice Exam and Study Guides - Verified By DumpsTests Updated 95 Questions

2021 Updated Verified Pass GCCC Study Guides & Best Courses


GIAC GCCC Exam Syllabus Topics:

TopicDetails
Topic 1
  • Inventory and Control of Software Assets
  • Boundary Defense
Topic 2
  • Incident Response and Management
  • Background, History, Purpose & Implementation of the 20 CC
Topic 3
  • Secure Configurations for Network Devices
  • Application Software Security
Topic 4
  • Inventory and Control of Hardware Assets
  • Malware Defenses
Topic 5
  • Limitation and Control of Network Ports
  • Wireless Access Control
Topic 6
  • Implement a Security Awareness and Training Program
  • Controlled Access Based on the Need to Know

 

NEW QUESTION 30
Which of the following is necessary to automate a control for Inventory and Control of Hardware Assets?

  • A. A method of device scanning
  • B. An inventory of unauthorized assets
  • C. An up-to-date hardening guide
  • D. A centralized time server

Answer: A

 

NEW QUESTION 31
Kenya is a system administrator for SANS. Per the recommendations of the CIS Controls she has a dedicated host (kenya- adminbox / 10.10.10.10) for any administrative tasks. She logs into the dedicated host with her domain admin credentials. Which of the following connections should not exist from kenya-adminbox?

  • A. Firewall_charon.jane.org.22
  • B. Mail.jane.org.25
  • C. 10.10.10.33.443
  • D. 10.10.245.3389

Answer: B

 

NEW QUESTION 32
What is the relationship between a service and its associated port?

  • A. A service closes a port after a period of inactivity
  • B. A service opens the port and listens for network traffic
  • C. A service relies on the port to select the protocol
  • D. A service sets limits on the volume of traffic sent through the port

Answer: B

 

NEW QUESTION 33
Which of the following is necessary for implementing and automating the Continuous Vulnerability Assessment and Remediation CIS Control?

  • A. Software Whitelisting System
  • B. Penetration Testing System
  • C. System Configuration Enforcement System
  • D. Patch Management System

Answer: D

 

NEW QUESTION 34
A global corporation has major data centers in Seattle, New York, London and Tokyo. Which of the following is the correct approach from an intrusion detection and event correlation perspective?

  • A. Synchronize between Seattle and New York, and use local time for London and Tokyo
  • B. Configure all data center systems to use local time
  • C. Configure all data center systems to use GMT time
  • D. Configure all systems to use their default time settings

Answer: B

 

NEW QUESTION 35
Given the audit finding below, which CIS Control was being measured?

  • A. Controlled Use of Administrative Privilege
  • B. Inventory and Control of Hardware Assets
  • C. Controlled Access Based on the Need to Know
  • D. Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers
  • E. Limitation and Control of Network Ports, Protocols and Services

Answer: A

 

NEW QUESTION 36
IDS alerts at Service Industries are received by email. A typical day process over 300 emails with fewer than
50 requiring action. A recent attack was successful and went unnoticed due to the number of generated alerts.
What should be done to prevent this from recurring?

  • A. Increase the number of staff responsible for processing IDS alerts.
  • B. Change the alert method from email to text message.
  • C. Configure the IDS alerts to only alert on high priority systems.
  • D. Tune the IDS rules to decrease false positives.

Answer: D

 

NEW QUESTION 37
Beta corporation is doing a core evaluation of its centralized logging capabilities. The security staff suspects that the central server has several log files over the past few weeks that have had their contents changed. Given this concern, and the need to keep archived logs for log correction applications, what is the most appropriate next steps?

  • A. Store the files read-only and keep hashes of the logs separately.
  • B. Encrypt the log files with an asymmetric key and remove the cleartext version.
  • C. Keep the files in the log archives synchronized with another location.
  • D. Install a tier one timeserver on the network to keep log devices synchronized.

Answer: A

 

NEW QUESTION 38
Which projects enumerates or maps security issues to CVE?

  • A. CIS Controls
  • B. ISO 2700
  • C. SCAP
  • D. NIST

Answer: C

 

NEW QUESTION 39
How can the results of automated network configuration scans be used to improve the security of the network?

  • A. Reports can be sent to the CIO for performance benchmarks
  • B. Results can be provided to network engineers as actionable feedback
  • C. Scanners can correct network configurations issues
  • D. Results can be included in audit evidence failures

Answer: B

 

NEW QUESTION 40
What is the first step suggested before implementing any single CIS Control?

  • A. Perform a vulnerability scan
  • B. Develop a roll-out schedule
  • C. Develop an effectiveness test
  • D. Perform a gap analysis

Answer: D

 

NEW QUESTION 41
As part of a scheduled network discovery scan, what function should the automated scanning tool perform?

  • A. Alert the incident response team on ports and services added since the last scan
  • B. Uninstall listening services that have not been used since the last scheduled scan
  • C. Compare discovered ports and services to a known baseline to report deviations
  • D. Automatically close ports and services not included in the current baseline

Answer: C

 

NEW QUESTION 42
An administrator looking at a web application's log file found login attempts by the same host over several seconds. Each user ID was attempted with three different passwords. The event took place over 5 seconds.
* ROOT
* TEST
* ADMIN
* SQL
* USER
* NAGIOSGUEST
What is the most likely source of this event?

  • A. An IT administrator attempting to use outdated credentials to enter the site
  • B. An attempted Denial of Service attack by locking out administrative accounts
  • C. An automated tool that attempts to use a dictionary attack to infiltrate a website
  • D. An attempt to use SQL Injection to gain information from a web-connected database

Answer: C

 

NEW QUESTION 43
What is the list displaying?

  • A. Missing patches from a patching server
  • B. Allowed program in a software inventory application
  • C. Unauthorized programs detected in a software inventory
  • D. Installed software on an end-user device

Answer: B

 

NEW QUESTION 44
Janice is auditing the perimeter of the network at Sugar Water InC. According to documentation, external SMTP traffic is only allowed to and from 10.10.10.25. Which of the following actions would demonstrate the rules are configured incorrectly?

  • A. Receive spam from a known bad domain
  • B. Successfully deliver mail from another host inside the network directly to an external contact
  • C. Receive mail at Sugar Water Inc. account using Outlook as a mail client
  • D. Successfully deliver mail from web client using another host inside the network to an external contact.

Answer: B

 

NEW QUESTION 45
An organization has implemented a control for Controlled Use of Administrative Privileges. They are collecting audit data for each login, logout, and location for the root account of their MySQL server, but they are unable to attribute each of these logins to a specific user. What action can they take to rectify this?

  • A. Force the root account to only be accessible from the system console.
  • B. Force user accounts to use 'sudo' f or privileged use.
  • C. Turn on SELinux and user process accounting for the MySQL server.
  • D. Blacklist client applications from being run in privileged mode.

Answer: B

 

NEW QUESTION 46
Which of the following baselines is considered necessary to implement the Boundary Defense CIS Control?

  • A. Network Traffic/Service Baseline
  • B. Network Information Flow
  • C. Multi-Factor Authentication Standard
  • D. Network Device Configuration Baselines

Answer: B

 

NEW QUESTION 47
Which of the following assigns a number indicating the severity of a discovered software vulnerability?

  • A. CVSS
  • B. CCE
  • C. CPE
  • D. CVE

Answer: A

 

NEW QUESTION 48
Which of the following is a requirement in order to implement the principle of least privilege?

  • A. Mandatory Access Control (MAC)
  • B. Data normalization
  • C. Data classification
  • D. Discretionary Access Control (DAC)

Answer: C

 

NEW QUESTION 49
According to attack lifecycle models, what is the attacker's first step in compromising an organization?

  • A. Exploitation
  • B. Reconnaissance
  • C. Privilege Escalation
  • D. Initial Compromise

Answer: B

 

NEW QUESTION 50
A security incident investigation identified the following modified version of a legitimate system file on a compromised client:
C:\Windows\System32\winxml.dll Addition Jan. 16, 2014 4:53:11 PM
The infection vector was determined to be a vulnerable browser plug-in installed by the user. Which of the organization's CIS Controls failed?

  • A. Inventory and Control of Software Assets
  • B. Application Software Security
  • C. Maintenance, Monitoring, and Analysis of Audit Logs
  • D. Inventory and Control of Hardware Assets

Answer: A

 

NEW QUESTION 51
What is an organization's goal in deploying a policy to encrypt all mobile devices?

  • A. Applying the principle of defense in depth to their mobile devices
  • B. Enabling best practices for the protection of their software licenses
  • C. Controlling unauthorized access to sensitive information
  • D. Providing their employees, a secure method of connecting to the corporate network

Answer: C

 

NEW QUESTION 52
What is a recommended defense for the CIS Control for Application Software Security?

  • A. Run a dedicated vulnerability scanner against backend databases
  • B. Display system error messages for only non-kernel related events
  • C. Limit access to the web application production environment to just the developers
  • D. Keep debugging code in production web applications for quick troubleshooting

Answer: A

 

NEW QUESTION 53
John is implementing a commercial backup solution for his organization. Which of the following steps should be on the configuration checklist?

  • A. Develop a unique encryption scheme
  • B. Enable encryption if it 's not enabled by default
  • C. Disable software-level encryption to increase speed of transfer

Answer: B

 

NEW QUESTION 54
......

Ultimate Guide to the GCCC - Latest Edition Available Now: https://www.dumpstests.com/GCCC-latest-test-dumps.html

2021 Updated Verified Pass GCCC Exam - Real Questions & Answers: https://drive.google.com/open?id=1WWNIOlAq7s-XO2Sxr7B4GtU9m3Rl5A6d