← CSEC certification
CSEC practice questions
14 free sample questions in the same style as the live exam. Answers and explanations are revealed as you go — nothing here is scored.
Answered 0 of 14
0 correct
1. Which element of a data flow diagram represents a point where trust levels change?
FoundationThreat Modeling and Secure Architecture
2. An organization adopting zero trust wants to avoid granting broad network access based on VPN connection alone. What should replace this approach?
IntermediateThreat Modeling and Secure Architecture
3. When threat modeling a microservices architecture, which factor most complicates trust boundary analysis compared to a monolith?
AdvancedThreat Modeling and Secure Architecture
4. What does the 'principle of least privilege' state?
FoundationIdentity and Access Management
5. Which authentication factor category does a hardware security key (e.g., FIDO2 token) represent?
IntermediateIdentity and Access Management
6. In a zero trust model, why is machine and service identity management particularly challenging?
AdvancedIdentity and Access Management
7. Which algorithm is a widely used asymmetric encryption and digital signature algorithm?
FoundationApplied Cryptography
8. What is the main risk of using a deprecated hashing algorithm like MD5 for password storage?
IntermediateApplied Cryptography
9. What does an Indicator of Compromise (IOC) typically represent?
FoundationDetection Engineering and Incident Response
10. Why are tabletop exercises valuable for incident response readiness?
IntermediateDetection Engineering and Incident Response
11. An organization must select NIST SP 800-53 controls appropriate to its system's impact level. Which document guides this categorization process?
AdvancedGovernance, Risk, and Compliance
12. What is the primary goal of a vulnerability management program?
FoundationSecurity Operations and Resilience
13. CASE STUDY — Hill Country Credit Union suffers account takeovers where attackers intercept one-time codes sent by SMS. Which control most effectively addresses this specific attack?
IntermediateIdentity and Access Management
14. CASE STUDY — Barton Creek Logistics is hit by ransomware. Its backups ran nightly to a network share mounted on the same domain, and the share is now encrypted too. What practice would have prevented this outcome?
IntermediateSecurity Operations and Resilience
Ready for the real thing?
The live CSEC exam has 29 questions, runs for 75 minutes, and needs 80% to pass.
Book your exam