Courseiva

GSEC Malicious Code and Exploit Mitigation Practice Question

A medium-sized company's Windows workstations are being infected by malicious macro documents delivered as .docm email attachments. Employees routinely open these attachments because the macros appear to come from a trusted internal sender. The security team wants to stop the macro execution with the least disruption to legitimate business macros, which are used only by the finance department. Which mitigation should the team implement first?

⚠ Common exam trap

The trap here is assuming that email attachment filtering alone solves macro malware, when the execution decision actually happens inside the Office application and must be controlled by macro policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Group Policy to set the Microsoft Office macro notification setting to 'Disable all macros except digitally signed macros' and distribute a trusted publisher certificate to finance.

The correct control is a Group Policy macro setting that disables unsigned macros while allowing digitally signed macros, with a trusted publisher certificate deployed to finance. This blocks the malicious macro execution path for nearly all users, preserves the legitimate finance macros, and requires no changes to email flow or third-party tools. It is the least disruptive, targeted mitigation for macro-borne malware in a Windows Office environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender Application Guard for Office to open untrusted documents in an isolated container.

    Why it's wrong here

    Application Guard for Office isolates untrusted documents in a hardware-based container, but it does not stop macro execution inside that container; the macro can still run and attempt network callbacks. The scenario requires blocking macro execution for most users while allowing finance macros, which is a policy-based control. Application Guard adds latency and complexity without addressing the allow/deny decision for macros, so it is not the first and least disruptive mitigation here.

  • ✗

    Configure an email gateway rule to strip all .docm attachments and quarantine them for administrator review.

    Why it's wrong here

    Stripping .docm attachments blocks one delivery path but not the underlying macro execution risk; attackers can rename extensions, use .xlsm, or deliver via cloud links. It also disrupts finance's legitimate macro workflow and creates an administrative burden. The scenario asks for the least disruptive control that stops macro execution while preserving finance macros, so an attachment-stripping rule is too blunt and incomplete compared with a macro policy.

  • ✓

    Use Group Policy to set the Microsoft Office macro notification setting to 'Disable all macros except digitally signed macros' and distribute a trusted publisher certificate to finance.

    Why this is correct

    This policy blocks unsigned macros for all users while permitting finance's signed macros, directly addressing the infection vector with minimal business impact. Trusted publisher certificates let finance macros run without prompts, and all other unsigned macros are silently blocked. This is the standard Group Policy control for exactly this scenario and does not require third-party tooling or network changes, making it the correct first step.

  • ✗

    Deploy an endpoint detection and response agent and create a detection rule that alerts when WINWORD.EXE spawns a child process.

    Why it's wrong here

    EDR detection of WINWORD.EXE spawning child processes is a valuable detection, but it is not a preventive mitigation and will generate many false positives from legitimate macro-driven workflows. The scenario asks for a mitigation that stops macro execution with least disruption, not monitoring. Detection without prevention leaves the infection path open, so this is not the correct first control.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.