GSEC · domain
Endpoint Security
GSEC endpoint security covers hardening Windows and Linux hosts, detecting malware that evades disk, and controlling what code may execute. Questions present incident scenarios or policy exhibits and ask you to choose the correct forensic artifact, Group Policy or AppLocker outcome, or layered control, so you must know native tools and their actual behavior.
Focused practice
Practice Endpoint Security questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Endpoint Security
Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.
Memory analysis with Volatility or similar tools to find injected, file-less malware in RAM
AppLocker and Software Restriction Policies rules governing execution from user-writable paths like AppData
Windows Defender Application Control and driver signing enforcement for kernel-mode code integrity
Defense-in-depth ransomware controls: patching, least privilege, backups, EDR, and network segmentation
Watch out for
Common Endpoint Security exam traps
- ▸Assuming antivirus file scanning detects file-less malware; only memory or behavioral analysis reveals code living solely in RAM.
- ▸Believing AppLocker default rules allow execution from AppData; user-writable paths are commonly blocked by path or publisher rules.
- ▸Confusing driver signature enforcement with Secure Boot or HVCI; each blocks different unsigned or tampered kernel code paths.
Question index
All Endpoint Security questions (13)
Click any question to see the full explanation, or start a practice session above.
A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)
Medium2Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?
Medium3A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?
Medium4A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?
Medium5Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?
Medium6A small business wants to protect its Windows endpoints from malware delivered through email attachments and malicious websites. The owner asks a security consultant for a single built-in Windows feature that can provide real-time antivirus scanning, cloud-based protection, and automatic updates without purchasing third-party software. Which Windows feature should the consultant recommend?
Easy7When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?
Medium8When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?
Medium9A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)
Medium10A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?
Hard11A healthcare provider must protect laptops that store electronic protected health information (ePHI). The security team wants to ensure that if a laptop is lost or stolen, the data on the drive remains confidential even if an attacker removes the drive and connects it to another computer. The team also wants to minimize the risk of cold-boot attacks that could extract encryption keys from memory. Which full disk encryption configuration best meets these requirements?
Hard12A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?
Easy13An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?
HardOther domains
All GSEC exam domains
Frequently asked questions
- What does the Endpoint Security domain cover on the GSEC exam?
- Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.
- How many questions are in this domain?
- This page lists all 13 Endpoint Security questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Endpoint Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.