Courseiva

GSEC Windows Security Infrastructure Practice Question

An organization is implementing a Windows Defender Application Control (WDAC) policy to block unauthorized executables on Windows 10 endpoints. The security team wants to ensure that only signed binaries from trusted publishers are allowed to run, but they also need to allow a specific in-house application that is not signed. What is the most appropriate approach?

⚠ Common exam trap

The trap here is thinking that publisher rules can be used for unsigned applications, but they require a valid signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a hash rule to allow the specific unsigned application by its file hash.

WDAC allows exceptions for specific files using hash rules. This is the most appropriate method to permit an unsigned application while still enforcing the policy for all other executables. Hash rules are precise and secure because they tie the exception to the exact file content. Disabling WDAC, using publisher rules without a signature, or switching to audit mode would either weaken security or not work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a hash rule to allow the specific unsigned application by its file hash.

    Why this is correct

    WDAC supports hash rules, which allow executables based on their unique file hash. This is ideal for unsigned applications that need to be whitelisted. The hash ensures that only that exact file is allowed, and any modification changes the hash, preventing tampering. This approach maintains a strong security posture while permitting the necessary application.

  • ✗

    Create a publisher rule for the in-house application's certificate, even though it is not signed.

    Why it's wrong here

    Publisher rules require a valid digital signature from a trusted publisher. If the application is not signed, there is no certificate to base a publisher rule on. Therefore, this approach is not possible without first signing the application, which may not be feasible.

  • ✗

    Set WDAC to audit mode so that the unsigned application can run without being blocked.

    Why it's wrong here

    Audit mode only logs what would have been blocked; it does not enforce the policy. While it allows the application to run, it also allows all other unauthorized executables to run, providing no protection. Audit mode is for testing, not for production enforcement.

  • ✗

    Disable WDAC enforcement for the entire endpoint to allow the unsigned application to run.

    Why it's wrong here

    Disabling WDAC entirely would remove all application control protections, allowing any executable to run, which defeats the purpose of the policy. This is a poor security practice and does not selectively allow the application while maintaining protection for other software.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.