GSEC Malicious Code and Exploit Mitigation Practice Question
A security team is hardening a fleet of Windows 10 workstations against exploit techniques used by malicious code. The team wants to enable operating system features that make it harder for an attacker to execute arbitrary code in memory and to bypass address space randomization. Which two features should the team enable? (Choose two.)
⚠ Common exam trap
The trap here is selecting real mitigations that are configured in audit or opt-in mode, which log or partially apply the protection instead of fully enforcing it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Address Space Layout Randomization (ASLR) with system-wide mandatory enforcement.
Data Execution Prevention and system-wide mandatory Address Space Layout Randomization are the two operating system features that directly raise the bar for memory-corruption exploits. DEP prevents execution of code from data pages, defeating simple shellcode placement, while mandatory ASLR randomizes memory layout so attackers cannot rely on fixed addresses. Together they force attackers to find information leaks or other bypasses, which is the intended hardening posture for the workstation fleet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Address Space Layout Randomization (ASLR) with system-wide mandatory enforcement.
Why this is correct
ASLR randomizes the base addresses of executable images, DLLs, the stack, and the heap, which makes it difficult for an attacker to reliably predict where code or gadgets reside. Enforcing ASLR system-wide through Windows Defender Exploit Guard's mandatory ASLR setting ensures that even applications not compiled with ASLR support are randomized, increasing the difficulty of exploitation. This is the second correct hardening feature for the scenario.
- ✗
Control Flow Guard (CFG) configured only for applications that opt in.
Why it's wrong here
Control Flow Guard restricts indirect call targets to a validated list, which is a strong mitigation against control-flow hijacking. However, configuring it only for applications that opt in leaves many third-party and legacy binaries unprotected, so the fleet-wide hardening goal is not met. The scenario calls for operating system features that broadly raise exploitation difficulty, and an opt-in-only CFG configuration does not deliver that coverage.
- ✗
Structured Exception Handling Overwrite Protection (SEHOP) in audit-only mode.
Why it's wrong here
SEHOP is a real Windows mitigation that validates the structured exception handling chain to block SEH overwrite exploits, but running it in audit-only mode merely logs what would have been blocked rather than preventing the exploit. The scenario asks for features that make code execution and ASLR bypass harder, so an audit-only configuration does not provide the protective effect. SEHOP should be enabled in enforced mode to be effective.
- ✓
Data Execution Prevention (DEP) in opt-out mode.
Why this is correct
DEP marks memory pages as non-executable unless they are explicitly intended for code, which prevents an attacker from executing shellcode placed on the stack or heap. In opt-out mode, DEP applies to all processes except those explicitly excluded, providing broad coverage. This directly mitigates the classic exploit technique of writing payload to data memory and jumping to it, making it one of the two correct features to enable.
- ✗
Windows Defender Application Control (WDAC) in audit mode.
Why it's wrong here
WDAC is an application control feature that restricts which binaries and scripts may run, which is valuable for blocking unauthorized code. In audit mode, however, it only records what would have been blocked and does not enforce the policy, so it does not actively prevent execution. The scenario asks for features that hinder in-memory code execution and ASLR bypass, and an audit-only application control policy does not provide that enforcement.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.