Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 4Objective 2

Endpoint Security GSEC Practice Questions (Page 5)

Part of the Endpoint and Platform Security domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~30–51 in this domain), expect 3–6 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
6concepts

Questions 21–25

  1. 21application · medium

    A company wants to prevent users from installing unauthorized software on their Windows workstations. The security team has decided to implement application control. Which approach is most effective while minimizing administrative overhead?

    Select an answer first
  2. 22expert · hard

    A security team is evaluating endpoint protection platforms. They need to detect fileless malware that runs in memory, and they also need to enforce application control. The team has a limited budget and wants to minimize the number of agents. Which solution is most suitable?

    Select an answer first
  3. 23expert · hard

    An EDR alert shows that a workstation ran a PowerShell script that downloaded an executable and executed it. The script was not blocked by application control because PowerShell is allowed. The security team needs to respond while minimizing business disruption. Which action is most appropriate?

    Select an answer first
  4. 24application · medium

    A small business uses a mix of Windows 10 and Windows 11 laptops. The owner wants to ensure that all laptops receive security updates promptly without requiring user intervention. The laptops are not domain-joined and are used both inside and outside the office. Which solution is the most appropriate?

    Select an answer first
  5. 25application · medium

    An organization's security team suspects a laptop is compromised after an employee clicked a link in a phishing email. The EDR console shows suspicious process activity but no confirmed malware file. The incident responder needs to preserve evidence and understand the scope. Which action should be taken first?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.