GCCC Actual Questions Answers PDF 100% Cover Real Exam Questions [Q21-Q45]

Share

GCCC Actual Questions Answers PDF 100% Cover Real Exam Questions

GCCC Exam questions and answers 


GIAC GCCC Exam Syllabus Topics:

TopicDetails
Topic 1
  • Incident Response and Management
  • Background, History, Purpose & Implementation of the 20 CC
Topic 2
  • Secure Configurations for Network Devices
  • Application Software Security
Topic 3
  • Inventory and Control of Hardware Assets
  • Malware Defenses
Topic 4
  • Maintenance, Monitoring, and Analysis of Audit Logs
  • Account Monitoring and Control
Topic 5
  • Limitation and Control of Network Ports
  • Wireless Access Control
Topic 6
  • Inventory and Control of Software Assets
  • Boundary Defense
Topic 7
  • Implement a Security Awareness and Training Program
  • Controlled Access Based on the Need to Know
Topic 9
  • Penetration Tests and Red Team Exercises
  • Controlled Use of Administrative Privileges
Topic 10
  • Email & Web Browser Protections
  • Data Recovery Capability
  • Data Protection
Topic 11
  • Secure Configurations for Hardware and Software
  • Continuous Vulnerability Management

 

NEW QUESTION 21
According to attack lifecycle models, what is the attacker's first step in compromising an organization?

  • A. Reconnaissance
  • B. Privilege Escalation
  • C. Initial Compromise
  • D. Exploitation

Answer: A

 

NEW QUESTION 22
An organization has installed a firewall for Boundary Defense. It allows only outbound traffic from internal workstations for web and SSH, allows connections from the internet to the DMZ, and allows guest wireless access to the internet only. How can an auditor validate these rules?

  • A. Try to send email from a wireless guest account
  • B. Try to access the internal network from the wireless router
  • C. Check for packets going from the Internet to the Web server
  • D. Check for packages going from the web server to the user workstations

Answer: B

 

NEW QUESTION 23
Which approach is recommended by the CIS Controls for performing penetration tests?

  • A. Complete intrusive tests on test systems
  • B. Utilize a single attack vector at a time
  • C. Document a single vulnerability per system
  • D. Execute all tests during network maintenance windows

Answer: A

 

NEW QUESTION 24
An organization has implemented a policy to continually detect and remove malware from its network. Which of the following is a detective control needed for this?

  • A. Network Intrusion Prevention sends alerts when RST packets are received
  • B. Network Intrusion Detection devices sends alerts when signatures are updated
  • C. Host-based firewall sends alerts when packets are sent to a closed port
  • D. Host-based anti-virus sends alerts to a central security console

Answer: D

 

NEW QUESTION 25
Scan 1 was taken on Monday. Scan 2 was taken of the same network on Wednesday. Which of the following findings is accurate based on the information contained in the scans?

  • A. The host located at 192.168.177.7 is no longer on the network
  • B. The host with MAC Address D8:50:E6:9F:EE:60 is no longer on the network
  • C. The host located at 192.168.177.21 is a new host on the network
  • D. The host with MAC Address D8:50:E6:9F:EE:60 had an IP address change

Answer: D

 

NEW QUESTION 26
Which of the following is a responsibility of a change management board?

  • A. Reviewing log files for unapproved changes
  • B. Approving system baseline configurations.
  • C. Reviewing configuration of the documents
  • D. Providing recommendations for the changes

Answer: B

 

NEW QUESTION 27
An organization is implementing an application software security control their custom-written code that provides web-based database access to sales partners. Which action will help mitigate the risk of the application being compromised?

  • A. Providing the source code for their web application to existing sales partners
  • B. Logging the connection requests to the web application server from outside hosts
  • C. Identifying high-risk assets that are on the same network as the web application server
  • D. Creating signatures for their IDS to detect attacks specific to their web application

Answer: D

 

NEW QUESTION 28
What tool creates visual network topology output and results that can be analyzed by Ndiff to determine if a service or network asset has changed?

  • A. Zenmap
  • B. Netscreen
  • C. Ngrep
  • D. CIS-CAT

Answer: A

 

NEW QUESTION 29
Which CIS Control includes storing system images on a hardened server, scanning production systems for out-of-date software, and using file integrity assessment tools like tripwire?

  • A. Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
  • B. Continuous Vulnerability Management
  • C. Secure Configurations for Network Devices such as Firewalls, Routers and Switches
  • D. Inventory of Authorized and Unauthorized Software

Answer: A

 

NEW QUESTION 30
An analyst investigated unused organizational accounts. The investigation found that:
-10% of accounts still have their initial login password, indicating they were never used
-10% of accounts have not been used in over six months
Which change in policy would mitigate the security risk associated with both findings?

  • A. Accounts without login activity for 15 days are automatically locked
  • B. Accounts must have passwords of at least 8 characters, with one number or symbol
  • C. Users are required to change their password at the next login after three months

Answer: A

 

NEW QUESTION 31
Which activity increases the risk of a malware infection?

  • A. Reading email using a plain text email client
  • B. Charging a smartphone using a computer USB port
  • C. Editing webpages with a Linux system
  • D. Online banking in Incognito mode

Answer: B

 

NEW QUESTION 32
Why is it important to enable event log storage on a system immediately after it is installed?

  • A. To create the ability to separate abnormal behavior from normal behavior during an incident
  • B. To allow system to be restored to a known good state if it is compromised
  • C. To identify root kits included on the system out of the box
  • D. To compare it performance with other systems already on the network

Answer: A

 

NEW QUESTION 33
An organization has implemented a control for Controlled Use of Administrative Privileges. They are collecting audit data for each login, logout, and location for the root account of their MySQL server, but they are unable to attribute each of these logins to a specific user. What action can they take to rectify this?

  • A. Blacklist client applications from being run in privileged mode.
  • B. Force the root account to only be accessible from the system console.
  • C. Turn on SELinux and user process accounting for the MySQL server.
  • D. Force user accounts to use 'sudo' f or privileged use.

Answer: D

 

NEW QUESTION 34
What is the business goal of the Inventory and Control of Software Assets Control?

  • A. Accurate software versions are captured to enable patching
  • B. Only authorized software should be installed on the agency 's c omput er s ys t ems
  • C. Accurate software versions and counts are documented for licensing updates
  • D. All software conforms to licensing requirements for the business

Answer: B

 

NEW QUESTION 35
Acme Corporation is doing a core evaluation of its centralized logging capabilities. Which of the following scenarios indicates a failure in more than one CIS Control?

  • A. The loghost is missing logs from 3 servers in the inventory
  • B. The loghost time is out-of-sync with an external host
  • C. The loghost is receiving logs from hosts with different timezone values
  • D. The loghost is receiving out-of-sync logs from undocumented servers

Answer: D

 

NEW QUESTION 36
An administrator looking at a web application's log file found login attempts by the same host over several seconds. Each user ID was attempted with three different passwords. The event took place over 5 seconds.
* ROOT
* TEST
* ADMIN
* SQL
* USER
* NAGIOSGUEST
What is the most likely source of this event?

  • A. An automated tool that attempts to use a dictionary attack to infiltrate a website
  • B. An attempt to use SQL Injection to gain information from a web-connected database
  • C. An attempted Denial of Service attack by locking out administrative accounts
  • D. An IT administrator attempting to use outdated credentials to enter the site

Answer: A

 

NEW QUESTION 37
How can the results of automated network configuration scans be used to improve the security of the network?

  • A. Reports can be sent to the CIO for performance benchmarks
  • B. Results can be provided to network engineers as actionable feedback
  • C. Scanners can correct network configurations issues
  • D. Results can be included in audit evidence failures

Answer: B

 

NEW QUESTION 38
Which of the following assigns a number indicating the severity of a discovered software vulnerability?

  • A. CVE
  • B. CCE
  • C. CPE
  • D. CVSS

Answer: D

 

NEW QUESTION 39
What is the first step suggested before implementing any single CIS Control?

  • A. Develop an effectiveness test
  • B. Develop a roll-out schedule
  • C. Perform a gap analysis
  • D. Perform a vulnerability scan

Answer: C

 

NEW QUESTION 40
An auditor is focusing on potential vulnerabilities. Which of the following should cause an alert?

  • A. Fully patched guest machine that is not in the asset inventory
  • B. Workstation on which a domain admin has never logged in
  • C. Server that has zero browser plug-ins
  • D. Windows host with an uptime of 382 days

Answer: D

 

NEW QUESTION 41
Which of the following should be measured and analyzed regularly when implementing the Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers CIS Control?

  • A. How long does it take to identify new unauthorized listening ports on the network systems
  • B. What percentage of the organization's applications are using sandboxing products
  • C. How long does it take to remove unauthorized software from the organization's systems
  • D. What percentage of assets will have their settings enforced and redeployed
  • E. What percentage of systems in the organization are using Network Level Authentication (NLA)

Answer: D

 

NEW QUESTION 42
Implementing which of the following will decrease spoofed e-mail messages?

  • A. Finger Protocol
  • B. Internet Message Access Protocol
  • C. Network Address Translation
  • D. Sender Policy Framework

Answer: D

 

NEW QUESTION 43
When evaluating the Wireless Access Control CIS Control, which of the following systems needs to be tested?

  • A. 802.1x authentication systems
  • B. Log management system
  • C. Data classification and access baselines
  • D. PII data scanner

Answer: A

 

NEW QUESTION 44
Which of the following archiving methods would maximize log integrity?

  • A. Magnetic Tape
  • B. CD-RW
  • C. USB flash drive
  • D. DVD-R

Answer: D

 

NEW QUESTION 45
......

DumpsTorrent GCCC  Exam Practice Test Questions : https://www.dumpstorrent.com/GCCC-exam-dumps-torrent.html

Pass GCCC Exam Info and Free Practice Test : https://drive.google.com/open?id=1U998ucQg1C_Df0rFjewoQLeIW0Mvcj8f