
GIAC Security Essentials
Domain 5Objective 3
Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 2)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 6–10
- 6
Which type of malware is characterized by encrypting a victim's files and demanding payment for the decryption key?
Select an answer first - 7
An analyst is investigating a malware sample that appears to be a legitimate utility but also collects keystrokes and sends them to a remote server. How should this malware be classified?
Select an answer first - 8
A security team is analyzing a malware sample that uses a known exploit to gain code execution. They want to determine if the exploit would be mitigated by ASLR and DEP on the target system. Which analysis approach is MOST appropriate?
Select an answer first - 9
A user reports that after plugging in a USB drive found in the parking lot, their files were encrypted and a ransom note appeared. The security team later determines the USB contained an autorun script that downloaded additional payloads. Which classification best describes the initial USB component, and which propagation method did it use?
Select an answer first - 10
A company's endpoint protection solution uses application whitelisting. A user needs to run a new internal tool that is not yet approved. What is the most appropriate action for the security team?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.