
GIAC Security Essentials
Domain 5Objective 3
Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 1)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 1–5
- 1
A security analyst discovers a file that, when executed, installs a backdoor and then attempts to spread itself to other systems by exploiting a network service vulnerability. Which type of malicious code does this describe?
Select an answer first - 2
After a malware infection has been contained and eradicated, which incident response step involves restoring systems from clean backups and verifying normal operation?
Select an answer first - 3
A company experiences a ransomware outbreak that encrypts files on several file servers. The IT team has restored the servers from backups, but they are concerned about reinfection. Which step is MOST important to prevent reinfection?
Select an answer first - 4
A software company wants to test a suspicious binary in an isolated environment. They need to observe its network connections and file system changes without risking the host. Which approach BEST meets this requirement?
Select an answer first - 5
A user visits a compromised website and their browser automatically downloads and executes malware without any user interaction. Which infection vector is this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.