Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.
Start practicing
Endpoint Security — choose a session length
Free · No account required
Domain overview
GSEC endpoint security covers hardening Windows and Linux hosts, detecting malware that evades disk, and controlling what code may execute. Questions present incident scenarios or policy exhibits and ask you to choose the correct forensic artifact, Group Policy or AppLocker outcome, or layered control, so you must know native tools and their actual behavior.
Exam objectives
Memory analysis with Volatility or similar tools to find injected, file-less malware in RAM
AppLocker and Software Restriction Policies rules governing execution from user-writable paths like AppData
Windows Defender Application Control and driver signing enforcement for kernel-mode code integrity
Defense-in-depth ransomware controls: patching, least privilege, backups, EDR, and network segmentation
Assuming antivirus file scanning detects file-less malware; only memory or behavioral analysis reveals code living solely in RAM.
Believing AppLocker default rules allow execution from AppData; user-writable paths are commonly blocked by path or publisher rules.
Confusing driver signature enforcement with Secure Boot or HVCI; each blocks different unsigned or tampered kernel code paths.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?
2Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?
3When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?
4An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?
5When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?
6A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?
7A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)
8A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?
9A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?
10A healthcare provider must protect laptops that store electronic protected health information (ePHI). The security team wants to ensure that if a laptop is lost or stolen, the data on the drive remains confidential even if an attacker removes the drive and connects it to another computer. The team also wants to minimize the risk of cold-boot attacks that could extract encryption keys from memory. Which full disk encryption configuration best meets these requirements?
11A small business wants to protect its Windows endpoints from malware delivered through email attachments and malicious websites. The owner asks a security consultant for a single built-in Windows feature that can provide real-time antivirus scanning, cloud-based protection, and automatic updates without purchasing third-party software. Which Windows feature should the consultant recommend?
12A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?
13A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)
Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.
The Courseiva GSEC question bank contains 13 questions in the Endpoint Security domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included