Skip to main content

GCCC Online Exam

GIAC Critical Controls Certification (GCCC)

93 questions available ยท Page 1 of 10

View study plans
Question 1 Single choice

Kenya is a system administrator for SANS. Per the recommendations of the CIS Controls she has a dedicated host (kenya-adminbox / 10.10.10.10) for any administrative tasks. She logs into the dedicated host with her domain admin credentials.

Which of the following connections should not exist from kenya-adminbox?

  1. A

    10.10.245.3389

  2. B

    Mail.jane.org.25

  3. C

    Firewall_charon.jane.org.22

  4. D

    10.10.10.33.443

Show answer and explanation

Correct answer: B

Question 2 Single choice

DHCP logging output in the screenshot would be used for which of the following?

  1. A

    Enforcing port-based network access control to prevent unauthorized devices on the network.

  2. B

    Identifying new connections to maintain an up-to-date inventory of devices on the network.

  3. C

    Detecting malicious activity by compromised or unauthorized devices on the network.

  4. D

    Providing ping sweep results to identify live network hosts for vulnerability scanning.

Show answer and explanation

Correct answer: B

Question 3 Single choice

What is the relationship between a service and its associated port?

  1. A

    A service closes a port after a period of inactivity

  2. B

    A service relies on the port to select the protocol

  3. C

    A service sets limits on the volume of traffic sent through the port

  4. D

    A service opens the port and listens for network traffic

Show answer and explanation

Correct answer: D

Question 4 Single choice

A global corporation has major data centers in Seattle, New York, London and Tokyo.

Which of the following is the correct approach from an intrusion detection and event correlation perspective?

  1. A

    Configure all data center systems to use local time

  2. B

    Configure all data center systems to use GMT time

  3. C

    Configure all systems to use their default time settings

  4. D

    Synchronize between Seattle and New York, and use local time for London and Tokyo

Show answer and explanation

Correct answer: A

Question 5 Single choice

Which of the following best describes the CIS Controls?

  1. A

    Technical, administrative, and policy controls based on research provided by the SANS Institute

  2. B

    Technical controls designed to provide protection from the most damaging attacks based on current threat data

  3. C

    Technical controls designed to augment the NIST 800 series

  4. D

    Technical, administrative, and policy controls based on current regulations and security best practices

Show answer and explanation

Correct answer: B

Question 6 Single choice

A security incident investigation identified the following modified version of a legitimate system file on a compromised client:

C:\Windows\System32\winxml.dll Addition Jan. 16, 2014 4:53:11 PM

The infection vector was determined to be a vulnerable browser plug-in installed by the user.

Which of the organization's CIS Controls failed?

  1. A

    Application Software Security

  2. B

    Inventory and Control of Software Assets

  3. C

    Maintenance, Monitoring, and Analysis of Audit Logs

  4. D

    Inventory and Control of Hardware Assets

Show answer and explanation

Correct answer: B

Question 7 Single choice

The settings in the screenshot would be configured as part of which CIS Control?

  1. A

    Application Software Security

  2. B

    Inventory and Control of Hardware Assets

  3. C

    Account Monitoring and Control

  4. D

    Controlled Use of Administrative Privileges

Show answer and explanation

Correct answer: B

Question 8 Single choice

Based on the data shown below.

Which wireless access point has the manufacturer default settings still in place?

  1. A

    Starbucks

  2. B

    Linksys

  3. C

    Hhonors

  4. D

    Interwebz

Show answer and explanation

Correct answer: B

Question 9 Single choice

An organization has implemented a policy to detect and remove malicious software from its network.

Which of the following actions is focused on correcting rather than preventing attack?

  1. A

    Configuring a firewall to only allow communication to whitelisted hosts and ports

  2. B

    Using Network access control to disable communication by hosts with viruses

  3. C

    Disabling autorun features on all workstations on the network

  4. D

    Training users to recognize potential phishing attempts

Show answer and explanation

Correct answer: B

Question 10 Single choice

Acme Corporation is doing a core evaluation of its centralized logging capabilities.

Which of the following scenarios indicates a failure in more than one CIS Control?

  1. A

    The loghost is missing logs from 3 servers in the inventory

  2. B

    The loghost is receiving logs from hosts with different timezone values

  3. C

    The loghost time is out-of-sync with an external host

  4. D

    The loghost is receiving out-of-sync logs from undocumented servers

Show answer and explanation

Correct answer: D