Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

GCED Exam Dumps - GIAC Security Certification: GASF Questions and Answers

Question # 4

A company estimates a loss of $2,374 per hour in sales if their website goes down. Their webserver hosting site’s documented downtime was 7 hours each quarter over the last two years. Using the information, what can the analyst determine?

Options:

A.

Annualized loss expectancy

B.

CVSS risk score

C.

Total cost of ownership

D.

Qualitative risk posture

Buy Now
Question # 5

When attempting to collect data from a suspected system compromise, which of the following should generally be collected first?

Options:

A.

The network connections and open ports

B.

The contents of physical memory

C.

The current routing table

D.

A list of the running services

Buy Now
Question # 6

Which command tool can be used to change the read-only or hidden setting of the file in the screenshot?

Options:

A.

attrib

B.

type

C.

tasklist

D.

dir

Buy Now
Question # 7

Which statement below is the MOST accurate about insider threat controls?

Options:

A.

Classification of information assets helps identify data to protect.

B.

Security awareness programs have a minimal impact on reducing the insider threat.

C.

Both detective and preventative controls prevent insider attacks.

D.

Rotation of duties makes an insider threat more likely.

E.

Separation of duties encourages one employee to control a great deal of information.

Buy Now
Question # 8

Monitoring the transmission of data across the network using a man-in-the-middle attack presents a threat against which type of data?

Options:

A.

At-rest

B.

In-transit

C.

Public

D.

Encrypted

Buy Now
Question # 9

A security device processes the first packet from 10.62.34.12 destined to 10.23.10.7 and recognizes a malicious anomaly. The first packet makes it to 10.23.10.7 before the security devices sends a TCP RST to 10.62.34.12. What type of security device is this?

Options:

A.

Host IDS

B.

Active response

C.

Intrusion prevention

D.

Network access control

Buy Now
Question # 10

You have been tasked with searching for Alternate Data Streams on the following collection of Windows partitions; 2GB FAT16, 6GB FAT32, and 4GB NTFS. How many total Gigabytes and partitions will you need to search?

Options:

A.

4GBs of data, the NTFS partition only.

B.

12GBs of data, the FAT16, FAT32, and NTFS partitions.

C.

6GBs of data, the FAT32 partition only.

D.

10GBs of data, both the FAT32 and NTFS partitions.

Buy Now
Question # 11

An outside vulnerability assessment reveals that users have been routinely accessing Gmail from work for over a year, a clear violation of this organization’s security policy. The users report “it just started working one day”. Later, a network administrator admits he meant to unblock Gmail for just his own IP address, but he made a mistake in the firewall rule.

Which security control failed?

Options:

A.

Access control

B.

Authentication

C.

Auditing

D.

Rights management

Buy Now
Question # 12

To detect worms and viruses buried deep within a network packet payload, Gigabytes worth of traffic content entering and exiting a network must be checked with which of the following technologies?

Options:

A.

Proxy matching

B.

Signature matching

C.

Packet matching

D.

Irregular expression matching

E.

Object matching

Buy Now
Question # 13

Following a Digital Forensics investigation, which of the following should be included in the final forensics report?

Options:

A.

An executive summary that includes a list of all forensic procedures performed.

B.

A summary of the verified facts of the incident and the analyst’s unverified opinions.

C.

A summary of the incident and recommended disciplinary actions to apply internally.

D.

An executive summary that includes high level descriptions of the overall findings.

Buy Now
Exam Code: GCED
Exam Name: GIAC Certified Enterprise Defender
Last Update: Aug 24, 2025
Questions: 88
GCED pdf

GCED PDF

$25.5  $84.99
GCED Engine

GCED Testing Engine

$28.5  $94.99
GCED PDF + Engine

GCED PDF + Testing Engine

$40.5  $134.99