GSEC Malicious Code and Exploit Mitigation Practice Question
A security engineer is hardening a fleet of Windows servers that run a legacy business application. The application vendor requires that the servers retain the ability to run unsigned macros for compatibility. Which mitigation strategy best reduces the risk of malicious macro-based code execution while maintaining the application's required functionality?
⚠ Common exam trap
The trap here is treating macro execution itself as the only thing to block, when the stronger mitigation for mandatory unsigned macros is to constrain the post-exploitation behaviors they enable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement Attack Surface Reduction rules that block Office applications from creating child processes and from injecting code into other processes.
Because the vendor insists on unsigned macros, the control must target what macros do after they run rather than whether they are trusted. Attack Surface Reduction rules that block Office child process creation and process injection stop the common execution chain used by macro malware while leaving legitimate macro logic intact, achieving the required balance between compatibility and risk reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Defender Application Guard for Office and open all macro-enabled documents in the isolated container.
Why it's wrong here
Application Guard for Office opens untrusted documents in a hardware-isolated container, which is effective for user-facing Office clients, but the legacy application runs server-side and does not use the interactive Office container. This control would not intercept the server's macro execution path and therefore cannot satisfy the vendor's requirement while reducing risk on these servers.
- ✗
Add all internal file servers to the Trusted Locations list so macros in documents from those locations run without security prompts.
Why it's wrong here
Trusted Locations bypass macro security checks for files in specified paths, which increases risk rather than reducing it. If an attacker writes a malicious macro-enabled document to a trusted share, it would execute silently. This approach does not mitigate malicious macro behavior and actively weakens the protection posture on the servers.
- ✗
Set the Trust Center macro notification setting to Disable all macros without notification for all Office applications on the servers.
Why it's wrong here
Disabling all macros without notification blocks the legacy application's required unsigned macros entirely, violating the vendor's compatibility requirement. Although it would prevent malicious macro execution, it also breaks the business application, so it is not an acceptable mitigation strategy for this environment.
- ✓
Implement Attack Surface Reduction rules that block Office applications from creating child processes and from injecting code into other processes.
Why this is correct
ASR rules such as blocking Office child process creation and process injection target the behaviors that macro-based malware relies on, regardless of whether the macro itself is signed. This preserves the ability to run the required unsigned macros while preventing the most common payload delivery and execution techniques, directly matching the scenario's need to reduce malicious macro risk without breaking functionality.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.