GSEC Malicious Code and Exploit Mitigation Practice Question
A small business owner is concerned about ransomware encrypting critical files on a shared network drive. The owner wants a solution that can restore files quickly after an attack without paying the ransom. Which of the following is the MOST effective control to achieve this?
⚠ Common exam trap
The trap here is assuming that antivirus or file versioning alone can guarantee recovery, when in fact ransomware often targets or encrypts those very mechanisms, making offline backups essential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a regular backup strategy that includes offline and offsite copies.
A robust backup strategy with offline and offsite copies is the most effective way to recover from ransomware. It ensures that a clean copy of data is available regardless of the attack's success. While other controls can help prevent or limit damage, only backups provide a reliable restoration path without paying the ransom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy antivirus software with real-time scanning on all endpoints.
Why it's wrong here
Antivirus software can detect and block known ransomware, but it is not foolproof against new or polymorphic variants. It does not provide a recovery mechanism if files are encrypted. The scenario specifically asks for a way to restore files, so antivirus alone is insufficient.
- ✓
Implement a regular backup strategy that includes offline and offsite copies.
Why this is correct
Regular backups that are kept offline and offsite ensure that even if ransomware encrypts the network drive, a clean copy of the data exists and can be restored. This is the most reliable way to recover from ransomware without paying. It directly addresses the need to restore files quickly and effectively.
- ✗
Configure the network drive to be read-only for all users.
Why it's wrong here
Making the network drive read-only would prevent users from modifying files, which would also stop ransomware from encrypting them. However, it would also prevent legitimate work, making it impractical for a shared drive that users need to write to. It is not a viable solution for most business needs.
- ✗
Enable file versioning on the shared network drive.
Why it's wrong here
File versioning can help recover previous versions of files, but if ransomware encrypts the files and the versioning history is stored on the same drive, it may also be encrypted or deleted. It is not as robust as offline backups. Versioning is a useful supplement but not the most effective standalone control for ransomware recovery.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.