
GIAC Security Essentials
Domain 4Objective 2
Endpoint Security GSEC Practice Questions (Page 3)
Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
6concepts
Questions 11–15
- 11
A company is migrating from on-premises servers to cloud-based productivity applications. The security team wants to ensure that endpoints are protected against web-based threats. The company has a limited budget and cannot afford a full EDR solution. Which combination of controls would provide the most cost-effective protection?
Select an answer first - 12
An employee receives an email that appears to be from the company's CEO, asking the employee to purchase gift cards and send the codes. The email's domain is slightly misspelled (e.g., company.com vs. cornpany.com). The employee clicks the link and enters their credentials on a fake login page. Which type of attack has occurred, and which endpoint control would have been most effective in preventing the credential theft?
Select an answer first - 13
A small business wants to harden its Windows workstations against common malware and unauthorized changes. The owner wants a solution that is low-cost and does not require additional software purchases. Which hardening measure is most effective and immediately applicable?
Select an answer first - 14
A company has a mix of Windows and macOS endpoints. The security team wants to enforce a policy that requires full-disk encryption on all endpoints. The team also needs to be able to remotely wipe a device if it is lost or stolen. Which solution provides centralized management for both platforms?
Select an answer first - 15
An organization's EDR solution alerts on a workstation that is beaconing to a known command-and-control domain. The alert includes the process name, the user, and the destination IP. The security team needs to determine if other endpoints are affected. Which EDR capability is most useful for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.