Courseiva

GSEC Malicious Code and Exploit Mitigation Practice Question

A security analyst at a financial firm discovers that a user's workstation is executing a malicious macro embedded in a Microsoft Word document. The macro is attempting to download a second-stage payload from a remote server. The analyst wants to prevent this specific type of attack from succeeding on other workstations while allowing legitimate macros to run. Which of the following is the MOST effective mitigation?

⚠ Common exam trap

The trap here is assuming that disabling all macros is the only way to stop macro malware, overlooking the more granular 'Block macros from the Internet' policy that preserves legitimate macro functionality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Office's 'Block macros from running in Office files from the Internet' policy via Group Policy.

The 'Block macros from running in Office files from the Internet' policy is specifically designed to mitigate macro-based malware delivered via email or web downloads. It uses Mark-of-the-Web to identify files from untrusted sources and blocks macro execution while allowing macros in trusted local files. This balances security with usability, making it the most effective targeted mitigation for the described attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all macros without notification in the Trust Center settings for all Office applications.

    Why it's wrong here

    While disabling all macros without notification would prevent the malicious macro from running, it also blocks legitimate macros that the organization may rely on for business processes. This approach is overly restrictive and would disrupt productivity. The scenario specifically requires allowing legitimate macros, so this is not the best choice.

  • ✗

    Deploy a web proxy that blocks all outbound traffic to unknown domains to prevent payload download.

    Why it's wrong here

    Blocking outbound traffic to unknown domains might prevent the second-stage payload download, but it does not stop the initial macro execution. The macro could still perform other malicious actions, such as encrypting local files or spreading laterally. This is a network-level control that does not address the root cause of the macro execution.

  • ✗

    Implement an application whitelist that only allows signed Microsoft Office executables to run.

    Why it's wrong here

    Application whitelisting of Office executables would not prevent malicious macros from running because the macros execute within the trusted Office process. The macro code runs inside WINWORD.EXE, which is already allowed. This control is ineffective against macro-based attacks that abuse legitimate applications.

  • ✓

    Enable Microsoft Office's 'Block macros from running in Office files from the Internet' policy via Group Policy.

    Why this is correct

    This policy, available in Office 2016 and later, blocks macros in files that originate from the Internet (e.g., downloaded from email or web). It directly addresses the scenario where a user opens a malicious document from an external source, while still allowing macros in trusted internal files. It is a targeted, effective control that does not require disabling macros entirely.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.