GSEC Endpoint Security Practice Question
A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?
⚠ Common exam trap
Test-takers frequently confuse application control mechanisms like AppLocker with kernel-mode driver integrity enforcement, which requires a Code Integrity policy under Device Guard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device Guard with Code Integrity policies
Device Guard with Code Integrity policies enforces that only trusted, signed kernel-mode drivers can load, directly preventing unsigned or tampered drivers from being used for rootkits. BitLocker, AppLocker, and Windows Defender Firewall address different security concerns—data encryption, application control, and network filtering—and do not provide kernel-mode driver integrity enforcement. Therefore, Device Guard is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows Defender Firewall with Advanced Security
Why it's wrong here
Windows Defender Firewall controls network traffic based on rules, not driver loading. It cannot prevent unsigned or malicious kernel-mode drivers from executing. While it is a valuable defense-in-depth component, it does not address driver integrity or rootkit prevention. Consequently, it is not the correct feature for enforcing signed driver requirements.
- ✗
BitLocker with TPM and PIN
Why it's wrong here
BitLocker provides full-disk encryption to protect data at rest, not to control which drivers can load. While it prevents unauthorized access to the disk, it does not validate driver signatures or block unsigned kernel-mode drivers. Enabling BitLocker would not stop a rootkit from loading if an attacker gains execution privileges. Thus, it does not satisfy the requirement for driver integrity enforcement.
- ✗
AppLocker with default rules
Why it's wrong here
AppLocker is designed to restrict which applications and scripts users can run, primarily in user mode. It does not enforce kernel-mode driver signing or prevent unsigned drivers from loading. While it can block some executables, it is not the appropriate control for kernel-level driver integrity. Therefore, it does not meet the requirement to allow only approved drivers.
- ✓
Device Guard with Code Integrity policies
Why this is correct
Device Guard (now part of Windows Defender Application Control) uses Code Integrity policies to enforce that only trusted, signed kernel-mode drivers and user-mode binaries can execute. It blocks unsigned or malicious drivers from loading, directly preventing rootkit installation. This is the correct choice because it specifically controls driver signing and integrity at the kernel level, meeting the requirement to allow only approved drivers.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.