Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Essentials

Domain 5Objective 3

Malicious Code & Exploit Mitigation GSEC Practice Questions (Page 8)

Part of the Security Operations and Incident Response domain, which makes up ~16% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 36–40

  1. 36application · medium

    A malware analyst receives a suspicious executable and needs to determine its capabilities without executing it. Which approach should the analyst use?

    Select an answer first
  2. 37application · medium

    During incident response, a forensic analyst identifies a file that appears to be a keylogger. The analyst needs to determine if the file is malicious without risking further infection. Which approach is most appropriate?

    Select an answer first
  3. 38foundation · easy

    Which endpoint protection mechanism uses a predefined list of approved applications and blocks all others from executing?

    Select an answer first
  4. 39foundation · easy

    Which type of malware analysis involves examining the code of a malicious file without executing it?

    Select an answer first
  5. 40expert · hard

    A security analyst is investigating a system that is sending sensitive data to an external server. The analyst suspects spyware. The system is critical and cannot be taken offline. Which approach best balances the need to gather evidence and maintain operations?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSEC” is a trademark of its owner, used for identification only.