← CSEC certification

CSEC practice questions

14 free sample questions in the same style as the live exam. Answers and explanations are revealed as you go — nothing here is scored.

Answered 0 of 14

0 correct

  1. 1. Which element of a data flow diagram represents a point where trust levels change?

    Foundation

    Threat Modeling and Secure Architecture

  2. 2. An organization adopting zero trust wants to avoid granting broad network access based on VPN connection alone. What should replace this approach?

    Intermediate

    Threat Modeling and Secure Architecture

  3. 3. When threat modeling a microservices architecture, which factor most complicates trust boundary analysis compared to a monolith?

    Advanced

    Threat Modeling and Secure Architecture

  4. 4. What does the 'principle of least privilege' state?

    Foundation

    Identity and Access Management

  5. 5. Which authentication factor category does a hardware security key (e.g., FIDO2 token) represent?

    Intermediate

    Identity and Access Management

  6. 6. In a zero trust model, why is machine and service identity management particularly challenging?

    Advanced

    Identity and Access Management

  7. 7. Which algorithm is a widely used asymmetric encryption and digital signature algorithm?

    Foundation

    Applied Cryptography

  8. 8. What is the main risk of using a deprecated hashing algorithm like MD5 for password storage?

    Intermediate

    Applied Cryptography

  9. 9. What does an Indicator of Compromise (IOC) typically represent?

    Foundation

    Detection Engineering and Incident Response

  10. 10. Why are tabletop exercises valuable for incident response readiness?

    Intermediate

    Detection Engineering and Incident Response

  11. 11. An organization must select NIST SP 800-53 controls appropriate to its system's impact level. Which document guides this categorization process?

    Advanced

    Governance, Risk, and Compliance

  12. 12. What is the primary goal of a vulnerability management program?

    Foundation

    Security Operations and Resilience

  13. 13. CASE STUDY — Hill Country Credit Union suffers account takeovers where attackers intercept one-time codes sent by SMS. Which control most effectively addresses this specific attack?

    Intermediate

    Identity and Access Management

  14. 14. CASE STUDY — Barton Creek Logistics is hit by ransomware. Its backups ran nightly to a network share mounted on the same domain, and the share is now encrypted too. What practice would have prevented this outcome?

    Intermediate

    Security Operations and Resilience

Ready for the real thing?

The live CSEC exam has 29 questions, runs for 75 minutes, and needs 80% to pass.

Book your exam