
GIAC Security Operations Certified
Domain 1Objective 2
Endpoint Defense GSOC Practice Questions (Page 5)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
Questions 21–25
- 21
What is the primary function of a host-based firewall on an endpoint?
Select an answer first - 22
During an incident, an analyst discovers that a compromised endpoint was used to access a sensitive database. The analyst needs to determine what data was accessed and whether it was exfiltrated. The database logs are not centralized. Which action is the most appropriate?
Select an answer first - 23
A user reports that their cursor moves on its own and files are being deleted. The security team suspects remote access trojan (RAT) activity. Which endpoint defense control is most likely to detect and block this behavior?
Select an answer first - 24
Which of the following is a common endpoint threat that relies on tricking a user into performing an action, such as opening a malicious attachment?
Select an answer first - 25
A user receives a phishing email with a malicious macro-enabled document. The user opens the document, and the macro downloads and executes a payload. Which endpoint defense technology would have been MOST effective at preventing this attack chain?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.