최신GIAC Critical Controls Certification (GCCC) - GCCC무료샘플문제
문제1
How can the results of automated network configuration scans be used to improve the security of the network?
How can the results of automated network configuration scans be used to improve the security of the network?
정답: C
문제2
Which of the options below will do the most to reduce an organization's attack surface on the internet?
Which of the options below will do the most to reduce an organization's attack surface on the internet?
정답: C
문제3
Given the audit finding below, which CIS Control was being measured?

Given the audit finding below, which CIS Control was being measured?

정답: C
문제4
Which of the following should be used to test antivirus software?
Which of the following should be used to test antivirus software?
정답: D
문제5
An organization has implemented a control for Controlled Use of Administrative Privilege. The control requires users to enter a password from their own user account before being allowed elevated privileges, and that no client applications (e.g. web browsers, e-mail clients) can be run with elevated privileges. Which of the following actions will validate this control is implemented properly?
An organization has implemented a control for Controlled Use of Administrative Privilege. The control requires users to enter a password from their own user account before being allowed elevated privileges, and that no client applications (e.g. web browsers, e-mail clients) can be run with elevated privileges. Which of the following actions will validate this control is implemented properly?
정답: A
문제6
Implementing which of the following will decrease spoofed e-mail messages?
Implementing which of the following will decrease spoofed e-mail messages?
정답: D
문제7
An organization is implementing an application software security control their custom-written code that provides web-based database access to sales partners. Which action will help mitigate the risk of the application being compromised?
An organization is implementing an application software security control their custom-written code that provides web-based database access to sales partners. Which action will help mitigate the risk of the application being compromised?
정답: B
문제8
Which of the following is a benefit of stress-testing a network?
Which of the following is a benefit of stress-testing a network?
정답: A
문제9
Which of the following statements is appropriate in an incident response report?
Which of the following statements is appropriate in an incident response report?
정답: C
문제10
Which of the following actions would best mitigate against phishing attempts such as the example below?

Which of the following actions would best mitigate against phishing attempts such as the example below?

정답: C