Courseiva
Endpoint Security →mediumMultiple Select

GSEC Endpoint Security Practice Question

A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)

⚠ Common exam trap

The trap here is assuming that more security products or user convenience always improve security, when disabling UAC or adding a second antivirus actually increases risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable PowerShell Constrained Language Mode for all users

Disabling Windows Script Host and enforcing PowerShell Constrained Language Mode both reduce the attack surface by limiting common attacker execution techniques. WSH is often abused for script-based malware, and Constrained Language Mode restricts PowerShell's ability to load arbitrary code. Together they harden endpoints without requiring third-party tools, while the other options either weaken security or introduce conflicts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable User Account Control (UAC) to improve user productivity

    Why it's wrong here

    Disabling UAC removes the prompt that requires elevation for administrative actions, allowing processes to run with higher privileges without user consent. This increases the risk of privilege escalation and silent malware execution. UAC is a security boundary that helps prevent unauthorized changes, so disabling it is the opposite of hardening. It would weaken endpoint security rather than reduce the attack surface.

  • ✗

    Install a second third-party antivirus alongside Microsoft Defender Antivirus

    Why it's wrong here

    Running two antivirus products simultaneously can cause performance issues, conflicts, and false positives, and it may force Microsoft Defender Antivirus into passive mode. It does not add layered protection in a reliable way and can leave gaps if one product interferes with the other. The scenario asks for hardening measures, and installing a competing antivirus is not a recommended way to reduce attack surface.

  • ✗

    Enable the Guest account and assign it a blank password for temporary access

    Why it's wrong here

    Enabling the Guest account with a blank password creates an easily exploitable entry point. Attackers can use it to gain initial access or move laterally without credentials. Best practice is to keep the Guest account disabled. This action increases the attack surface rather than reducing it, so it is not an appropriate endpoint hardening measure for the administrator to implement.

  • ✓

    Enable PowerShell Constrained Language Mode for all users

    Why this is correct

    Constrained Language Mode restricts PowerShell to a limited set of language features and blocks access to arbitrary .NET types and COM objects. This significantly hinders attackers who rely on PowerShell for fileless malware and post-exploitation. Enforcing it for all users is a valid hardening step that reduces the attack surface while still allowing many administrative scripts to run, so it is an appropriate measure.

  • ✓

    Disable the Windows Script Host (WSH) to prevent execution of .vbs and .js scripts

    Why this is correct

    Disabling Windows Script Host prevents the execution of VBScript and JScript files, which are frequently used in phishing and malware campaigns to download or execute payloads. This reduces the attack surface without affecting most legitimate business applications. It is a recognized endpoint hardening measure that directly limits a common attacker technique, making it an appropriate action for the administrator to take.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.