Black Friday Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

GCCC GIAC Critical Controls Certification (GCCC) Questions and Answers

Questions 4

Which of the following items would be used reactively for incident response?

Options:

A.

A schedule for creating and storing backup

B.

A phone tree used to contact necessary personnel

C.

A script used to verify patches are installed on systems

D.

An IPS rule that prevents web access from international locations

Buy Now
Questions 5

Janice is auditing the perimeter of the network at Sugar Water InC. According to documentation, external SMTP traffic is only allowed to and from 10.10.10.25. Which of the following actions would demonstrate the rules are configured incorrectly?

Options:

A.

Receive spam from a known bad domain

B.

Receive mail at Sugar Water Inc. account using Outlook as a mail client

C.

Successfully deliver mail from another host inside the network directly to an external contact

D.

Successfully deliver mail from web client using another host inside the network to an external contact.

Buy Now
Questions 6

An organization is implementing a control within the Application Software Security CIS Control. How can they best protect against injection attacks against their custom web application and database applications?

Options:

A.

Ensure the web application server logs are going to a central log host

B.

Filter input to only allow safe characters and strings

C.

Configure the web server to use Unicode characters only

D.

Check user input against a list of reserved database terms

Buy Now
Questions 7

Which of the following best describes the CIS Controls?

Options:

A.

Technical, administrative, and policy controls based on research provided by the SANS Institute

B.

Technical controls designed to provide protection from the most damaging attacks based on current threat data

C.

Technical controls designed to augment the NIST 800 series

D.

Technical, administrative, and policy controls based on current regulations and security best practices

Buy Now
Questions 8

Acme Corporation is doing a core evaluation of its centralized logging capabilities. Which of the following scenarios indicates a failure in more than one CIS Control?

Options:

A.

The loghost is missing logs from 3 servers in the inventory

B.

The loghost is receiving logs from hosts with different timezone values

C.

The loghost time is out-of-sync with an external host

D.

The loghost is receiving out-of-sync logs from undocumented servers

Buy Now
Questions 9

What is the list displaying?

Options:

A.

Allowed program in a software inventory application

B.

Unauthorized programs detected in a software inventory

C.

Missing patches from a patching server

D.

Installed software on an end-user device

Buy Now
Questions 10

John is implementing a commercial backup solution for his organization. Which of the following steps should be on the configuration checklist?

Options:

A.

Enable encryption if it ’s not enabled by default

B.

Disable software-level encryption to increase speed of transfer

C.

Develop a unique encryption scheme

Buy Now
Questions 11

An auditor is focusing on potential vulnerabilities. Which of the following should cause an alert?

Options:

A.

Workstation on which a domain admin has never logged in

B.

Windows host with an uptime of 382 days

C.

Server that has zero browser plug-ins

D.

Fully patched guest machine that is not in the asset inventory

Buy Now
Questions 12

Which activity increases the risk of a malware infection?

Options:

A.

Charging a smartphone using a computer USB port

B.

Editing webpages with a Linux system

C.

Reading email using a plain text email client

D.

Online banking in Incognito mode

Buy Now
Questions 13

An attacker is able to successfully access a web application as root using ‘ or 1 = 1 . as the password. The successful access

indicates a failure of what process?

Options:

A.

Input Validation

B.

Output Sanitization

C.

URL Encoding

D.

Account Management

Buy Now
Exam Code: GCCC
Exam Name: GIAC Critical Controls Certification (GCCC)
Last Update: Nov 23, 2024
Questions: 93
GCCC pdf

GCCC PDF

$25.5  $84.99
GCCC Engine

GCCC Testing Engine

$30  $99.99
GCCC PDF + Engine

GCCC PDF + Testing Engine

$40.5  $134.99