You must identify attacker persistence and choose the strongest mitigation for each scenario: allowlisting for unauthorized execution, memory or behavioral detection for fileless code, and macro or ASR controls for legacy Windows servers. The key is picking deny-by-default and memory-based detection over signature scanning.
Start practicing
Malicious Code and Exploit Mitigation — choose a session length
Free · No account required
Domain overview
This GSEC domain covers how malicious code executes and persists, and the controls that stop it. Expect scenario questions on Linux web shells, fileless malware in memory, application allowlisting, and Windows macro hardening, where you must pick the most effective detection or mitigation rather than a plausible-sounding but weaker control.
Exam objectives
Detecting Linux web shell persistence via cron, systemd units, and modified .bashrc or profile scripts
Detecting fileless malware through memory analysis, Sysmon, and EDR behavioral telemetry rather than file scanning
Enforcing deny-by-default execution with Windows AppLocker or Software Restriction Policies
Hardening legacy Windows servers that require unsigned macros using ASR rules and Office Trust Center settings
Assuming antivirus file scanning catches fileless malware, when nothing is written to disk and only memory or script behavior reveals it
Confusing allowlisting with blocklisting: only a deny-by-default allowlist stops unknown or unauthorized executables
Overlooking Linux persistence outside cron, such as systemd services, rc.local, or shell startup files the attacker modified
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?
2Which security control is most effective at preventing the execution of unauthorized or malicious software by enforcing a 'deny-by-default' policy on a workstation?
3A security analyst is concerned about Fileless Malware attacks. Which technique is most effective for detecting code that resides only in memory without writing files to the disk?
4Which of the following describes the primary goal of using a 'Honeytoken' in an environment to mitigate malicious code and insider threats?
5Which THREE of the following are primary defensive strategies to mitigate the risk of 'Living off the Land' (LotL) attacks?
6A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?
7A security engineer is hardening a fleet of Windows servers that run a legacy business application. The application vendor requires that the servers retain the ability to run unsigned macros for compatibility. Which mitigation strategy best reduces the risk of malicious macro-based code execution while maintaining the application's required functionality?
8A security analyst at a financial firm discovers that a user's workstation is executing a malicious macro embedded in a Microsoft Word document. The macro is attempting to download a second-stage payload from a remote server. The analyst wants to prevent this specific type of attack from succeeding on other workstations while allowing legitimate macros to run. Which of the following is the MOST effective mitigation?
9A penetration tester is examining a Windows 10 system and discovers that a recent exploit leveraged a use-after-free vulnerability in a widely used PDF reader application. The exploit successfully achieved code execution. Which of the following mitigation technologies, when enabled, would have made this exploitation significantly more difficult by randomizing the memory locations of key data structures?
10A medium-sized company's Windows workstations are being infected by malicious macro documents delivered as .docm email attachments. Employees routinely open these attachments because the macros appear to come from a trusted internal sender. The security team wants to stop the macro execution with the least disruption to legitimate business macros, which are used only by the finance department. Which mitigation should the team implement first?
11A security analyst is reviewing an incident where a user's browser was exploited by a drive-by download. The analyst wants to confirm whether the exploit achieved code execution and established persistence. Which artifact should the analyst examine first to determine if a new service was created for persistence on the Windows host?
12A penetration tester is assessing a web application and finds that user input is reflected into an HTML page without encoding. The tester wants to demonstrate that an attacker could steal a victim's session cookie by injecting a script that sends the cookie to an external server. Which mitigation, when implemented by the developers, most directly prevents this specific cookie theft even if the input reflection remains?
13A small business owner is concerned about ransomware encrypting critical files on a shared network drive. The owner wants a solution that can restore files quickly after an attack without paying the ransom. Which of the following is the MOST effective control to achieve this?
14A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to determine how the attacker is maintaining access after reboots. Which artifact should the responder check first to identify a persistent mechanism on this Linux host?
15A security team is hardening a fleet of Windows 10 workstations against exploit techniques used by malicious code. The team wants to enable operating system features that make it harder for an attacker to execute arbitrary code in memory and to bypass address space randomization. Which two features should the team enable? (Choose two.)
16A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?
You must identify attacker persistence and choose the strongest mitigation for each scenario: allowlisting for unauthorized execution, memory or behavioral detection for fileless code, and macro or ASR controls for legacy Windows servers. The key is picking deny-by-default and memory-based detection over signature scanning.
The Courseiva GSEC question bank contains 16 questions in the Malicious Code and Exploit Mitigation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Malicious Code and Exploit Mitigation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included