Courseiva
Endpoint Security →mediumMultiple Select

GSEC Endpoint Security Practice Question

A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)

⚠ Common exam trap

The trap here is selecting network or disk encryption controls that seem security-related but do not address in-memory credential protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Credential Guard

Credential Guard and LSA protection directly protect credentials in memory. Credential Guard isolates derived credentials using virtualization-based security, preventing their theft. LSA protection blocks non-PPL processes from reading LSA memory, thwarting credential dumping tools. SMB signing, Windows Defender Firewall, and BitLocker address other security aspects but do not directly prevent credential theft from memory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Credential Guard

    Why this is correct

    Credential Guard uses virtualization-based security to isolate and protect derived domain credentials, such as NTLM hashes and Kerberos tickets, from being extracted by malware. It prevents pass-the-hash attacks by keeping these secrets in a secure container. This directly addresses credential theft and is a correct measure.

  • ✗

    Enable BitLocker with TPM

    Why it's wrong here

    BitLocker encrypts the disk to protect data at rest, which is useful if the device is lost or stolen. However, it does not protect credentials in memory during runtime or prevent pass-the-hash attacks on a running system. Therefore, it does not directly mitigate the described threats.

  • ✓

    Configure LSA protection

    Why this is correct

    LSA protection (RunAsPPL) prevents non-PPL processes from accessing the Local Security Authority process memory, blocking tools like Mimikatz from dumping credentials. It directly mitigates credential dumping attempts. This is a correct measure to protect credentials in memory.

  • ✗

    Enforce SMB signing

    Why it's wrong here

    SMB signing ensures the integrity and authenticity of SMB communications, preventing man-in-the-middle attacks and relay attacks. However, it does not protect credentials stored in memory or prevent pass-the-hash. While valuable, it does not directly mitigate credential theft from endpoint memory. Therefore, it is not a correct choice for this scenario.

  • ✗

    Deploy Windows Defender Firewall with domain profile

    Why it's wrong here

    Windows Defender Firewall controls network traffic but does not protect credentials in memory or prevent credential dumping. It can limit lateral movement but does not directly address pass-the-hash or credential theft. Thus, it is not a direct mitigation for the specified threats.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.