
GIAC Security Essentials
Domain 5Objective 3
Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 4)
Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 16–20
- 16
A malware analyst wants to understand what a suspicious binary does when executed, including which files it creates and which registry keys it modifies. Which analysis method is MOST appropriate?
Select an answer first - 17
A company's incident response team is handling a malware outbreak. The malware is a worm that spreads via SMB and also installs a backdoor. The team has isolated infected systems, but they need to eradicate the malware from the network. Which approach is MOST effective?
Select an answer first - 18
A company is considering implementing application whitelisting to prevent malware execution. However, they have a diverse environment with many legacy applications that are not centrally managed. Which challenge is MOST significant?
Select an answer first - 19
A company's security team discovers that a piece of malware is spreading through email attachments and also using a network vulnerability to propagate. The malware encrypts files and demands ransom. Which classification is MOST accurate?
Select an answer first - 20
A company's users frequently plug in USB drives that may contain malware. The IT team wants to reduce the risk of infection from removable media while still allowing legitimate use of USB drives. Which control is MOST appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.