
GIAC Security Operations Certified
Domain 1Objective 2
Endpoint Defense GSOC Practice Questions (Page 9)
Part of the Security Operations Fundamentals domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 5–8 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
7concepts
Questions 41–45
- 41
A company has a mix of Windows 10 and Windows 11 endpoints. The security team wants to enforce a consistent hardening baseline but must accommodate legacy applications that require local admin rights on a small set of machines. Which approach is most effective?
Select an answer first - 42
What is the primary purpose of enabling detailed logging on endpoints?
Select an answer first - 43
During an incident, an analyst needs to prove that a specific file was executed on a Windows endpoint. Which log source would provide the most reliable evidence of program execution?
Select an answer first - 44
An organization wants to protect endpoints from zero-day malware that has not yet been signatured. Which technology is most effective for this purpose?
Select an answer first - 45
Which configuration change is a recommended endpoint hardening practice to limit the impact of a compromised user account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.