Courseiva

GSEC Malicious Code and Exploit Mitigation Practice Question

A security analyst is concerned about Fileless Malware attacks. Which technique is most effective for detecting code that resides only in memory without writing files to the disk?

⚠ Common exam trap

Candidates often choose 'disk forensic imaging'. This is useless for fileless malware because the malicious code resides in RAM and never touches the physical hard drive storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enabling PowerShell Script Block Logging.

Fileless malware often uses legitimate tools like PowerShell or WMI to execute code in memory. To detect this, analysts must shift from file-based scanning to process-based monitoring. Logging PowerShell Script Block Logging (Event ID 4104) and capturing command-line arguments are essential. These logs provide visibility into the actual code being executed in memory, which is the only way to catch threats that bypass traditional signature-based disk scanners by living off the land.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploying a traditional antivirus signature update.

    Why it's wrong here

    Traditional antivirus relies on scanning files on disk. Fileless malware does not store its malicious payload as a file on the file system, rendering signature-based disk scanning ineffective. This approach fails to detect memory-resident threats that use standard system processes to carry out their operations.

  • ✓

    Enabling PowerShell Script Block Logging.

    Why this is correct

    PowerShell Script Block Logging records the full content of code executed by the PowerShell engine. Since fileless malware frequently uses obfuscated PowerShell scripts for execution, this logging mechanism captures the de-obfuscated commands in memory, allowing for detection of malicious activity that never touches the disk.

  • ✗

    Scanning the hard drive for unauthorized startup files.

    Why it's wrong here

    Startup files are only relevant for malware that uses persistence mechanisms on the disk. Fileless malware, by definition, operates in memory. Searching for startup files will not find the malicious code, as the threat does not rely on traditional file-based launch points to maintain its execution state.

  • ✗

    Performing integrity checks on system binaries.

    Why it's wrong here

    Integrity checks like hashing system files detect modifications to files. Fileless malware operates in memory and generally does not modify legitimate system binaries. Therefore, file integrity monitoring will report that the system is clean, providing a false sense of security while the malicious code executes in RAM.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.