Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 3

Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 3)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 11–15

  1. 11application · medium

    A company discovers that a worm has propagated across multiple departments, infecting hundreds of workstations. The incident response team has isolated infected systems from the network. What is the next step in the incident response process?

    Select an answer first
  2. 12application · medium

    A user reports that their system is infected with ransomware after visiting a compromised website. The website exploited a browser vulnerability to deliver the ransomware. Which infection vector and mitigation technique are most relevant?

    Select an answer first
  3. 13foundation · easy

    Which endpoint protection mechanism monitors system calls and network activity in real time to block suspicious behavior that may indicate malware?

    Select an answer first
  4. 14application · medium

    A small law firm reports that several workstations are displaying ransomware messages. The IT admin finds that the infection started after an employee opened a PDF from an unknown sender. The PDF contained an embedded script that downloaded and executed the ransomware. Which combination of controls would BEST reduce the risk of this specific infection vector recurring?

    Select an answer first
  5. 15application · medium

    An analyst discovers a file that copies itself to network shares and also drops a payload that encrypts user documents. The file does not require user interaction to spread. How should this malware be classified?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.