GSEC Endpoint Security Practice Question
A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)
⚠ Common exam trap
The trap here is assuming that more security products or user convenience always improve security, when disabling UAC or adding a second antivirus actually increases risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable PowerShell Constrained Language Mode for all users
Disabling Windows Script Host and enforcing PowerShell Constrained Language Mode both reduce the attack surface by limiting common attacker execution techniques. WSH is often abused for script-based malware, and Constrained Language Mode restricts PowerShell's ability to load arbitrary code. Together they harden endpoints without requiring third-party tools, while the other options either weaken security or introduce conflicts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable User Account Control (UAC) to improve user productivity
Why it's wrong here
Disabling UAC removes the prompt that requires elevation for administrative actions, allowing processes to run with higher privileges without user consent. This increases the risk of privilege escalation and silent malware execution. UAC is a security boundary that helps prevent unauthorized changes, so disabling it is the opposite of hardening. It would weaken endpoint security rather than reduce the attack surface.
- ✗
Install a second third-party antivirus alongside Microsoft Defender Antivirus
Why it's wrong here
Running two antivirus products simultaneously can cause performance issues, conflicts, and false positives, and it may force Microsoft Defender Antivirus into passive mode. It does not add layered protection in a reliable way and can leave gaps if one product interferes with the other. The scenario asks for hardening measures, and installing a competing antivirus is not a recommended way to reduce attack surface.
- ✗
Enable the Guest account and assign it a blank password for temporary access
Why it's wrong here
Enabling the Guest account with a blank password creates an easily exploitable entry point. Attackers can use it to gain initial access or move laterally without credentials. Best practice is to keep the Guest account disabled. This action increases the attack surface rather than reducing it, so it is not an appropriate endpoint hardening measure for the administrator to implement.
- ✓
Enable PowerShell Constrained Language Mode for all users
Why this is correct
Constrained Language Mode restricts PowerShell to a limited set of language features and blocks access to arbitrary .NET types and COM objects. This significantly hinders attackers who rely on PowerShell for fileless malware and post-exploitation. Enforcing it for all users is a valid hardening step that reduces the attack surface while still allowing many administrative scripts to run, so it is an appropriate measure.
- ✓
Disable the Windows Script Host (WSH) to prevent execution of .vbs and .js scripts
Why this is correct
Disabling Windows Script Host prevents the execution of VBScript and JScript files, which are frequently used in phishing and malware campaigns to download or execute payloads. This reduces the attack surface without affecting most legitimate business applications. It is a recognized endpoint hardening measure that directly limits a common attacker technique, making it an appropriate action for the administrator to take.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.