GIAC GFACT Certification Sample Questions

GFACT Dumps, GFACT PDF, GFACT VCE, GIAC Foundational Cybersecurity Technologies VCE, GIAC GFACT PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Foundational Cybersecurity Technologies (GFACT) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GFACT certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GFACT Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Foundational Cybersecurity Technologies (GFACT) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Foundational Cybersecurity Technologies exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GFACT Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GFACT Sample Questions:

01. An attacker collects the names and job titles of staff from the public web pages of an organization and notes which of its services are reachable from the internet, without attempting to log in to anything.
This activity belongs to the __________ stage of an attack.
a) reconnaissance
b) command and control
c) exploitation
d) installation
 
02. Once two parties hold a shared secret key, they use symmetric encryption rather than asymmetric encryption for the large volume of data that follows.
What is the reason for that choice?
a) Symmetric encryption produces output that no key can reverse, so the data stays protected
b) Symmetric encryption is considerably faster once there is a large volume of data to protect
c) Symmetric encryption removes any need for the two parties to agree on something in advance
d) Symmetric encryption is the only form that works on data held in storage rather than in transit
 
03. A security consultancy is preparing to test the systems of a client.
Which two conditions must be in place before the testing starts?
(Choose two.)
a) A record of the results of any previous test carried out on the same systems
b) Written permission from the owner of the systems to be tested
c) An assurance from the testers that nothing will be damaged during the test
d) An agreed scope setting out which systems the testers may and may not touch
 
04. What is the difference between authentication and authorization?
a) Authentication is a technical control, while authorization is a matter of written policy
b) Authentication establishes who a user is; authorization determines what that user may do
c) Authentication applies to people, while authorization applies to devices and services
d) Authentication determines what a user may do; authorization establishes who the user is
 
05. An attacker with access to an order database changes the delivery addresses on a number of records. Staff can still read every record, the database stays online throughout, and no copy of the data leaves the company.
Which property of the CIA triad has been harmed?
a) Confidentiality
b) Availability
c) Accountability
d) Integrity
 
06. An attacker obtains the correct password for a user from an unrelated breach and tries it against that user's work account, which is protected by multi-factor authentication.
Why does the sign-in attempt fail?
a) The password is rejected because it has appeared in a published breach list
b) A second factor of a different kind is required, which the attacker lacks
c) The password is treated as expired because it is presented from a new device
d) The account locks automatically after a single attempt from an unfamiliar location
 
07. Which two statements describe symmetric encryption?
(Choose two.)
a) The sender and the recipient use the same key
b) The key used to encrypt can be published openly
c) The key has to reach the other party before any protected data can be read
d) Each party holds a mathematically related pair of keys
 
08. A hospital adds a second internet connection and a backup power supply so that its patient record system keeps running if either the main line or the mains supply fails.
Which property of the CIA triad do these measures primarily support?
a) Confidentiality
b) Integrity
c) Availability
d) Authenticity
 
09. Two people who have never met need to exchange a confidential message. The recipient has published a public key in a directory that anyone can read.
How does the sender use it so that only the recipient can read the message?
a) Encrypt the message with the published public key, which only the matching private key can decrypt
b) Encrypt the message with the published public key, then have the recipient decrypt it with that same public key
c) Ask the recipient to send the private key first, so that both parties can encrypt and decrypt with it
d) Encrypt the message with the private key of the sender, so that anyone holding the matching public key can open it
 
10. A developer proposes storing customer records in Base64 form, arguing that they will be unreadable to anyone who opens the file and are therefore protected.
Which assessment of that proposal holds?
a) It holds, because Base64 output cannot be read without the matching decoding key
b) It fails, because Base64 is only a change of representation, and anyone at all can undo it without a key
c) It fails, because Base64 protects the records in transit and leaves them exposed in storage
d) It holds, because Base64 is a one-way transformation and the records cannot be recovered from it

Answers:

Question: 01
Answer: a
Question: 02
Answer: b
Question: 03
Answer: b, d
Question: 04
Answer: b
Question: 05
Answer: d
Question: 06
Answer: b
Question: 07
Answer: a, c
Question: 08
Answer: c
Question: 09
Answer: a
Question: 10
Answer: b

Note: For any error in GIAC Foundational Cybersecurity Technologies (GFACT) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.8 / 5 (46 votes)