GIAC GSEC (Security Essentials)

Attacks, Vulnerabilities & Web Security

22 practice questions with explanations — 15 free to try

2 of these 22 questions are in the free 15-question taster · the full topic is part of Premium

PassNova has 22 GIAC GSEC (Security Essentials) practice questions on Attacks, Vulnerabilities & Web Security, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.

Sample questions

Attacks, Vulnerabilities & Web Security: example questions & answers

2 worked examples with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 22-question Attacks, Vulnerabilities & Web Security bank is part of PassNova Premium.

  1. Which characteristic distinguishes a worm from a virus?

    • AIt must attach itself to a host program to run
    • BIt hides in the boot sector until the next restart
    • CIt only encrypts files and demands a ransom
    • DIt spreads across networks without any user action✓

    Answer: A worm is self-replicating and self-propagating: it exploits network services or stolen credentials to copy itself to other machines without anyone opening a file, as WannaCry did over SMBv1. A virus attaches to a host file or program and spreads when that is run or shared. Encrypting files for ransom describes ransomware, and hiding in the boot sector describes a boot-sector virus or bootkit.

  2. Which exploit mitigation marks stack and heap memory as non-executable, so that injected shellcode placed there cannot run?

    • AData Execution Prevention (DEP/NX)✓
    • BStack canaries added by the /GS compiler switch
    • CAddress Space Layout Randomization (ASLR)
    • DStructured Exception Handler Overwrite Protection

    Answer: DEP, backed by the processor's NX (no-execute) bit, marks data pages such as the stack and heap as non-executable, so jumping to shellcode there raises an access violation. Attackers respond with return-oriented programming, chaining existing executable code, which is why DEP is paired with ASLR. ASLR randomises where code and data live, SEHOP protects exception-handler chains, and /GS canaries detect stack buffer overwrites before a function returns.

Start practising Attacks, Vulnerabilities & Web Security →