GSEC Incident Handling and Response Practice Question
A security team is conducting a post-incident review after a successful ransomware attack. The team identifies that the initial infection vector was a phishing email that delivered a malicious macro. The team wants to improve future response. Which of the following actions is MOST effective for preventing a similar incident from succeeding in the future?
⚠ Common exam trap
The trap here is choosing a detective or user-dependent control like training or EDR when a preventive technical control that directly blocks the attack technique is available and more effective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable macros in Microsoft Office applications by default and only allow signed macros from trusted publishers.
The most effective action is to disable macros by default and allow only signed macros from trusted publishers. This directly prevents the malicious macro from executing, regardless of whether the phishing email reaches the user. It is a technical control that enforces a secure configuration and reduces the attack surface. While other measures like training, EDR, and email filtering add defense in depth, they are not as reliable in stopping this specific vector. Disabling macros is a best practice recommended by security organizations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable macros in Microsoft Office applications by default and only allow signed macros from trusted publishers.
Why this is correct
Disabling macros by default and allowing only signed macros from trusted publishers directly prevents the execution of malicious macros, which was the initial infection vector. This is a technical control that enforces a secure configuration and is highly effective because it blocks the attack technique regardless of user action. It aligns with the principle of least functionality and is a recommended security baseline.
- ✗
Implement a security awareness training program that teaches employees to recognize phishing emails.
Why it's wrong here
Security awareness training is valuable, but it is not the most effective technical control for preventing macro-based malware. Users can still be tricked, and training alone does not block the execution of malicious macros. While it reduces risk, it is less reliable than technical controls that enforce policy. The question asks for the most effective action, which should be a technical control that directly mitigates the vector.
- ✗
Deploy an endpoint detection and response (EDR) solution to detect and block malicious macro execution.
Why it's wrong here
An EDR solution can detect and block malicious activity, but it is not as deterministic as disabling macros by default. EDR relies on behavioral detection, which can sometimes miss novel or obfuscated attacks. While EDR is a valuable layer, the most effective prevention is to eliminate the attack surface by disabling macros unless explicitly trusted. EDR is a detective and responsive control, not a preventive one for this specific vector.
- ✗
Configure email filtering to block all emails with macro-enabled attachments.
Why it's wrong here
Blocking all macro-enabled attachments can be effective, but it may also block legitimate business documents and is not foolproof because attackers can use other file types or techniques to deliver macros. It is a useful control, but disabling macros at the application level is more comprehensive and prevents execution even if the email bypasses filtering. Email filtering is a preventive measure but does not address the root cause of macro execution.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.