Courseiva

GSEC Malicious Code and Exploit Mitigation Practice Question

A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?

⚠ Common exam trap

The trap here is assuming that disabling a scripting host or restricting script files stops all PowerShell abuse, when encoded commands can execute without any script file on disk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable PowerShell script block logging and module logging through Group Policy, then collect the events in Windows Event Forwarding for analysis.

Encoded PowerShell commands hide the real script from casual command-line inspection, so the effective mitigation is to force PowerShell to log the de-obfuscated script blocks and module activity. Centralizing those events through Windows Event Forwarding lets analysts review the decoded payload and build detections, addressing both mitigation and evidence preservation without breaking legitimate administration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure AppLocker default rules to allow only administrators to run PowerShell scripts in the environment.

    Why it's wrong here

    AppLocker script rules can restrict who executes .ps1 files, but an encoded command passed with -EncodedCommand does not require a .ps1 file on disk and may run under the user's context. This control can reduce some risk but does not capture or decode the payload, so it fails to preserve investigative evidence for this specific incident.

  • ✗

    Disable the Windows Script Host on all workstations by setting the Enabled registry value under WSH settings to 0.

    Why it's wrong here

    Disabling Windows Script Host blocks .vbs, .js, and .wsf scripts executed through wscript.exe or cscript.exe, but it does not stop PowerShell from running an encoded command. The observed behavior is PowerShell-based, so this change leaves the exact execution path intact and produces no useful telemetry about the encoded payload on this workstation.

  • ✗

    Add the finance department's subnet to the Microsoft Defender Antivirus network inspection exclusion list.

    Why it's wrong here

    Adding a subnet to a network inspection exclusion list reduces Defender's ability to inspect network traffic for malicious activity; it does not block or record PowerShell execution. This action weakens detection and provides no visibility into the encoded command, making it counterproductive for investigating and mitigating the malicious code execution described.

  • ✓

    Enable PowerShell script block logging and module logging through Group Policy, then collect the events in Windows Event Forwarding for analysis.

    Why this is correct

    Script block logging records the de-obfuscated script content that PowerShell actually executes, even when the command line is Base64-encoded, and module logging captures pipeline execution details. Forwarding those events to a central collector preserves the decoded payload for investigation while giving defenders visibility into the malicious behavior, directly mitigating this encoded PowerShell execution scenario.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.