
GIAC Security Operations Certified
Domain 1Objective 2
Endpoint Defense GSOC Practice Questions (Page 10)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
Questions 46–50
- 46
A company wants to reduce the risk of malware spreading via USB drives. Which endpoint policy is the most effective?
Select an answer first - 47
In the context of security operations, what is the primary purpose of endpoint defense?
Select an answer first - 48
A security analyst notices repeated failed logon attempts followed by a successful logon on a single workstation at 3:00 AM. The EDR console shows a PowerShell process that downloaded a script from a file-sharing site and then executed it. The analyst needs to determine the scope of the activity. Which EDR capability is most directly suited to this task?
Select an answer first - 49
During incident response, an analyst finds that an attacker has been using a legitimate remote management tool to move laterally within the network. The tool is widely used by IT staff. The analyst needs to detect further malicious use of the tool without disrupting legitimate IT operations. Which approach is most effective?
Select an answer first - 50
An endpoint is confirmed to be infected with ransomware. The incident response team needs to preserve evidence while preventing further spread. Which action should be taken FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.