20+ practice questions focused on Endpoint Security — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Endpoint Security PracticeAn administrator observes unauthorized lateral movement via PowerShell Remoting on a Windows network. Which security control best mitigates this risk by restricting administrative access to specific jump hosts?
Explanation: Restricting WinRM access to specific source IP addresses ensures that only authorized jump servers can initiate remote management sessions. This technique, known as tiered administration, limits the blast radius of compromised credentials. By enforcing network-level filtering on the endpoint, administrators prevent attackers from leveraging PowerShell Remoting from arbitrary internal workstations, directly countering credential-based lateral movement tactics prevalent in modern enterprise environments.
An organization is deploying an Endpoint Detection and Response (EDR) solution. Which TWO of the following capabilities are primarily focused on post-compromise detection and investigation?
Explanation: EDR tools focus on behavioral analysis and forensic telemetry to identify threats that bypass traditional signature-based antivirus. By recording process execution, file modifications, and network connections, security teams can reconstruct the sequence of an attack. These capabilities are critical for incident response, allowing teams to determine the root cause, identify the scope of the infection, and perform precise remediation on affected endpoints without needing to reimage every device.
Which configuration best protects an endpoint against 'Pass-the-Hash' (PtH) attacks involving local administrator accounts?
Explanation: Pass-the-Hash attacks involve an attacker using an NTLM hash or Kerberos ticket to authenticate as a user without needing their password. By restricting the usage of local administrator accounts to specific workstations via Group Policy, the scope of these credentials is minimized. Combined with credential hardening, this makes it significantly harder for an attacker to move laterally using stolen hashes from memory.
A security analyst is investigating a Windows 10 workstation that has been compromised by a fileless malware attack. The malware executed entirely in memory and left no files on disk, but the analyst suspects the malicious code was injected into a legitimate process. Which native Windows feature should the analyst examine to identify the injected code and its origin?
Explanation: Event Tracing for Windows (ETW) with the Threat-Intelligence provider offers deep visibility into kernel and user-mode activities, including process injection and memory manipulation, which are hallmarks of fileless malware. Unlike traditional event logs or performance tools, ETW can trace the exact moment and source of code injection, enabling analysts to reconstruct the attack chain and identify the malicious process.
A financial institution is hardening its Linux servers against privilege escalation attacks. The security team wants to enforce that only binaries with a valid digital signature from approved vendors can execute with elevated privileges, while allowing unsigned binaries to run with normal user permissions. Which Linux kernel feature should the team implement to achieve this granular control?
Explanation: Linux Integrity Measurement Architecture (IMA) with appraisal and digital signatures enables the kernel to verify the cryptographic signature of an executable before it runs. This allows a policy where only binaries signed by trusted keys can execute with elevated privileges, while unsigned binaries may still run with standard user rights. This granular control is exactly what the financial institution needs to prevent privilege escalation via tampered or malicious binaries.
+15 more Endpoint Security questions available
Practice all Endpoint Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Endpoint Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Endpoint Security questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Endpoint Security is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Endpoint Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Endpoint Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Endpoint Security practice session with instant scoring and detailed explanations.
Start Endpoint Security Practice →