
GIAC Critical Controls Certification
Domain 5Objective 4
Malware Defenses GCCC Practice Questions (Page 6)
Part of the Security Operations and Monitoring domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~11–18 in this domain), expect 3–5 from this objective — we provide 50 practice questions to prepare you well beyond it. (estimate)
50questions here
10free pages
9concepts
Questions 26–30
- 26
A company has implemented endpoint protection and network filtering, but employees still fall for phishing emails that deliver trojans. Which additional control would most directly address this remaining risk?
Select an answer first - 27
An employee receives an email with an attachment that, when opened, installs a backdoor on the workstation. Which infection vector is primarily being used?
Select an answer first - 28
A user reports that a PDF attachment from an unknown sender launched a process that encrypted files and displayed a ransom note. The endpoint protection product did not alert on the PDF itself. Which detection gap most likely explains why the malware was not caught by the endpoint product?
Select an answer first - 29
A malware analyst needs to analyze a suspicious file that may contain a keylogger. The analyst wants to capture the file's behavior, including any network traffic, without exposing the corporate network. Which environment is most appropriate?
Select an answer first - 30
How does signature-based antivirus detect known malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.