Attacks, Vulnerabilities & Web Security
22 practice questions with explanations — 15 free to try
2 of these 22 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 22 GIAC GSEC (Security Essentials) practice questions on Attacks, Vulnerabilities & Web Security, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Attacks, Vulnerabilities & Web Security: example questions & answers
2 worked examples with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 22-question Attacks, Vulnerabilities & Web Security bank is part of PassNova Premium.
Which characteristic distinguishes a worm from a virus?
- AIt must attach itself to a host program to run
- BIt hides in the boot sector until the next restart
- CIt only encrypts files and demands a ransom
- DIt spreads across networks without any user action✓
Answer: A worm is self-replicating and self-propagating: it exploits network services or stolen credentials to copy itself to other machines without anyone opening a file, as WannaCry did over SMBv1. A virus attaches to a host file or program and spreads when that is run or shared. Encrypting files for ransom describes ransomware, and hiding in the boot sector describes a boot-sector virus or bootkit.
Which exploit mitigation marks stack and heap memory as non-executable, so that injected shellcode placed there cannot run?
- AData Execution Prevention (DEP/NX)✓
- BStack canaries added by the /GS compiler switch
- CAddress Space Layout Randomization (ASLR)
- DStructured Exception Handler Overwrite Protection
Answer: DEP, backed by the processor's NX (no-execute) bit, marks data pages such as the stack and heap as non-executable, so jumping to shellcode there raises an access violation. Attackers respond with return-oriented programming, chaining existing executable code, which is why DEP is paired with ASLR. ASLR randomises where code and data live, SEHOP protects exception-handler chains, and /GS canaries detect stack buffer overwrites before a function returns.