GIAC GCED Certification Sample Questions

GCED Dumps, GCED PDF, GCED VCE, GIAC Certified Enterprise Defender VCE, GIAC GCED PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Certified Enterprise Defender (GCED) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GCED certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GCED Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Certified Enterprise Defender (GCED) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Certified Enterprise Defender exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GCED Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GCED Sample Questions:

01. Before the testing window opens, a tester compiles staff names and email formats from public sources, a list of technologies from the client's recruitment adverts, and a set of host names from certificate transparency records.
What has this collection established?
a) A confirmed list of all the reachable services the client exposes to the internet.
b) A list of exploitable weaknesses, ready for the testing window to be planned.
c) A map of the client's internal network segments and the trust between them.
d) A picture of the target and candidate entry points, all of it still to be verified.
 
02. A tester has confirmed an injectable parameter in a production order-tracking application and has retrieved a single row to prove it. The finding will go into the technical report.
Which two items belong in the evidence for this finding?
(Choose two.)
a) A record of the time of each attempt and its source address.
b) The crafted request alongside the response that shows its effect.
c) The complete contents of the table the parameter gave access to.
d) The scanner confidence rating attached to the injectable parameter.
e) A copy of the application source file that builds and runs the database query.
 
03. The same host is scanned twice within an hour by the same vulnerability scanner. The first run is unauthenticated and returns three findings. The second supplies a local account with read access and returns forty-one, most of them naming installed packages and configuration settings.
What accounts for the difference?
a) The credentialed run exploited the candidate weaknesses and confirmed they exist.
b) The unauthenticated findings were false positives that authentication then eliminated.
c) The unauthenticated run was filtered at the host firewall and never reached most checks.
d) The credentialed run reads package and configuration state invisible to a probe.
 
04. Host discovery and a service scan have produced a list of live addresses with their listening ports and reported versions. The tester now moves on to enumeration.
What does enumeration add to what is already known?
a) The accounts, shares, endpoints and settings the reachable services disclose to callers.
b) The demonstrated impact of access obtained and used through one of these services.
c) The weaknesses that are plausibly exploitable, ranked by host, service and port.
d) The addresses that answered, and the ports found open across the estate.
 
05. A tester reports that a legacy internal application transmits credentials without transport encryption. The application's developer disputes the finding, stating that the configuration file enables encryption and that the scanner must be wrong.
How should the tester settle the question?
a) Ask the developer to reproduce the login and share the application-level log output.
b) Re-run the vulnerability scanner at higher verbosity and cite its confidence rating.
c) Read the configuration through an administrative session and confirm its value.
d) Capture the authentication exchange on the wire and show the credential in the payload.
 
06. Testing a production order system inside the agreed overnight window, a tester confirms an injectable parameter. The tool now offers to enumerate and dump the customer table, which the tester estimates holds several million rows.
What is the right course?
a) Continue the retrieval and treat the agreed window as authorization for it all.
b) Complete the dump and give the report a count of the records exposed.
c) Retrieve a minimal proof of the access and then stop short of any bulk retrieval.
d) Raise the request rate and finish the retrieval before the window closes.
 
07. Wireless testing is permitted at a client office. The client wants to know whether corporate laptops will associate with a network that merely presents the familiar corporate name, and what they send when they do.
Which activity answers that?
a) Capture a genuine association to the corporate network and crack the pre-shared key offline.
b) Enumerate the wireless controller's management interface for weak administrative credentials.
c) Survey the premises for already-present access points broadcasting the corporate name.
d) Stand up an access point advertising the corporate name and observe client behavior.
 
08. To keep a stable channel during a two-week engagement, the tester installed a scheduled task on three compromised servers, as the rules of engagement expressly permit. Testing has finished and the report is being written.
What must happen to the scheduled tasks?
a) Disabled on all three servers, with the task definitions left for the client to inspect.
b) Removed by the client's administrators, working from instructions supplied in the report.
c) Removed from all three servers, with the installation and the removal both recorded.
d) Left in place until the remediation retest and reused when that channel is needed.
 
09. An Nmap service scan of an in-scope host returns:
PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.4 (protocol 2.0) 443/tcp open ssl/http Apache httpd 2.4.6 3306/tcp open mysql MySQL 5.5.62
The tester intends to report a known weakness affecting the database release shown. What should be done first?
a) Record the finding at the severity the published risk-scoring scheme assigns to it.
b) Interact with the service to establish that the reported version is the running one.
c) Re-run the scan with a vulnerability scanner and report the entry that tool produces.
d) Check the vendor advisory covering that release and cite it as the finding's supporting evidence.
 
10. Directory data collected during an authorized internal test is rendered as a path: a helpdesk group holds a right to reset passwords on a service-desk account, that account belongs to a group with administrative rights over a jump server, and a domain administrator has an active session on that jump server.
What does the path establish?
a) A chain of existing rights that may permit escalation, still to be validated inside scope.
b) A set of missing patches on the jump server, permitting privilege escalation locally.
c) A confirmed escalation route that the tool has already exercised against the domain.
d) Evidence that an intruder might already have used these rights to reach the administrator.

Answers:

Question: 01
Answer: d
Question: 02
Answer: a, b
Question: 03
Answer: d
Question: 04
Answer: a
Question: 05
Answer: d
Question: 06
Answer: c
Question: 07
Answer: d
Question: 08
Answer: c
Question: 09
Answer: b
Question: 10
Answer: a

Note: For any error in GIAC Certified Enterprise Defender (GCED) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (77 votes)