GSEC Endpoint Security Practice Question
A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)
⚠ Common exam trap
The trap here is selecting network or disk encryption controls that seem security-related but do not address in-memory credential protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Credential Guard
Credential Guard and LSA protection directly protect credentials in memory. Credential Guard isolates derived credentials using virtualization-based security, preventing their theft. LSA protection blocks non-PPL processes from reading LSA memory, thwarting credential dumping tools. SMB signing, Windows Defender Firewall, and BitLocker address other security aspects but do not directly prevent credential theft from memory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Credential Guard
Why this is correct
Credential Guard uses virtualization-based security to isolate and protect derived domain credentials, such as NTLM hashes and Kerberos tickets, from being extracted by malware. It prevents pass-the-hash attacks by keeping these secrets in a secure container. This directly addresses credential theft and is a correct measure.
- ✗
Enable BitLocker with TPM
Why it's wrong here
BitLocker encrypts the disk to protect data at rest, which is useful if the device is lost or stolen. However, it does not protect credentials in memory during runtime or prevent pass-the-hash attacks on a running system. Therefore, it does not directly mitigate the described threats.
- ✓
Configure LSA protection
Why this is correct
LSA protection (RunAsPPL) prevents non-PPL processes from accessing the Local Security Authority process memory, blocking tools like Mimikatz from dumping credentials. It directly mitigates credential dumping attempts. This is a correct measure to protect credentials in memory.
- ✗
Enforce SMB signing
Why it's wrong here
SMB signing ensures the integrity and authenticity of SMB communications, preventing man-in-the-middle attacks and relay attacks. However, it does not protect credentials stored in memory or prevent pass-the-hash. While valuable, it does not directly mitigate credential theft from endpoint memory. Therefore, it is not a correct choice for this scenario.
- ✗
Deploy Windows Defender Firewall with domain profile
Why it's wrong here
Windows Defender Firewall controls network traffic but does not protect credentials in memory or prevent credential dumping. It can limit lateral movement but does not directly address pass-the-hash or credential theft. Thus, it is not a direct mitigation for the specified threats.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.