Want to pass your GIAC Critical Controls Certification (GCCC) GCCC exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
An organization has implemented a control for Controlled Use of Administrative Privilege. The control requires users to enter a password from their own user account before being allowed elevated privileges, and that no client applications (e.g. web browsers, e-mail clients) can be run with elevated privileges. Which of the following actions will validate this control is implemented properly?
A. Check the log entries to match privilege use with access from authorized users.
B. Run a script at intervals to identify processes running with administrative privilege.
C. Force the root account to only be accessible from the system console.
An organization has installed a firewall for Boundary Defense. It allows only outbound traffic from internal workstations for web and SSH, allows connections from the internet to the DMZ, and allows guest wireless access to the internet only. How can an auditor validate these rules?

A. Check for packets going from the Internet to the Web server
B. Try to send email from a wireless guest account
C. Check for packages going from the web server to the user workstations
D. Try to access the internal network from the wireless router
Which of the following will decrease the likelihood of eavesdropping on a wireless network?
A. Broadcasting in the 5Ghz frequency
B. Using Wired Equivalent Protocol (WEP)
C. Using EAP/TLS authentication and WPA2 with AES encryption
D. Putting the wireless network on a separate VLAN