Courseiva

GSEC · domain

Malicious Code and Exploit Mitigation

This GSEC domain covers how malicious code executes and persists, and the controls that stop it. Expect scenario questions on Linux web shells, fileless malware in memory, application allowlisting, and Windows macro hardening, where you must pick the most effective detection or mitigation rather than a plausible-sounding but weaker control.

16 questions3 easy7 medium6 hard

Focused practice

Practice Malicious Code and Exploit Mitigation questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Malicious Code and Exploit Mitigation

You must identify attacker persistence and choose the strongest mitigation for each scenario: allowlisting for unauthorized execution, memory or behavioral detection for fileless code, and macro or ASR controls for legacy Windows servers. The key is picking deny-by-default and memory-based detection over signature scanning.

Detecting Linux web shell persistence via cron, systemd units, and modified .bashrc or profile scripts

Detecting fileless malware through memory analysis, Sysmon, and EDR behavioral telemetry rather than file scanning

Enforcing deny-by-default execution with Windows AppLocker or Software Restriction Policies

Hardening legacy Windows servers that require unsigned macros using ASR rules and Office Trust Center settings

Watch out for

Common Malicious Code and Exploit Mitigation exam traps

  • ▸Assuming antivirus file scanning catches fileless malware, when nothing is written to disk and only memory or script behavior reveals it
  • ▸Confusing allowlisting with blocklisting: only a deny-by-default allowlist stops unknown or unauthorized executables
  • ▸Overlooking Linux persistence outside cron, such as systemd services, rc.local, or shell startup files the attacker modified

Question index

All Malicious Code and Exploit Mitigation questions (16)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following describes the primary goal of using a 'Honeytoken' in an environment to mitigate malicious code and insider threats?

Medium
2

Which THREE of the following are primary defensive strategies to mitigate the risk of 'Living off the Land' (LotL) attacks?

Medium
3

A security analyst is concerned about Fileless Malware attacks. Which technique is most effective for detecting code that resides only in memory without writing files to the disk?

Hard
4

A security analyst is reviewing an incident where a user's browser was exploited by a drive-by download. The analyst wants to confirm whether the exploit achieved code execution and established persistence. Which artifact should the analyst examine first to determine if a new service was created for persistence on the Windows host?

Medium
5

A small business owner is concerned about ransomware encrypting critical files on a shared network drive. The owner wants a solution that can restore files quickly after an attack without paying the ransom. Which of the following is the MOST effective control to achieve this?

Easy
6

An administrator identifies a suspicious process masquerading as a system service. To mitigate the risk while maintaining evidence, which action is the most appropriate first step in a professional incident response lifecycle?

Medium
7

Which security control is most effective at preventing the execution of unauthorized or malicious software by enforcing a 'deny-by-default' policy on a workstation?

Easy
8

A penetration tester is assessing a web application and finds that user input is reflected into an HTML page without encoding. The tester wants to demonstrate that an attacker could steal a victim's session cookie by injecting a script that sends the cookie to an external server. Which mitigation, when implemented by the developers, most directly prevents this specific cookie theft even if the input reflection remains?

Hard
9

A medium-sized company's Windows workstations are being infected by malicious macro documents delivered as .docm email attachments. Employees routinely open these attachments because the macros appear to come from a trusted internal sender. The security team wants to stop the macro execution with the least disruption to legitimate business macros, which are used only by the finance department. Which mitigation should the team implement first?

Easy
10

A security team is hardening a fleet of Windows 10 workstations against exploit techniques used by malicious code. The team wants to enable operating system features that make it harder for an attacker to execute arbitrary code in memory and to bypass address space randomization. Which two features should the team enable? (Choose two.)

Hard
11

A Windows workstation in the finance department suddenly starts launching PowerShell with an encoded command line shortly after a user opens a malicious Excel attachment. The endpoint has Microsoft Defender Antivirus enabled, but no PowerShell logging or script block logging is configured. Which action best mitigates this class of malicious code execution while preserving the ability to investigate the encoded payload?

Medium
12

A security analyst is reviewing a suspicious Windows 10 workstation. The analyst finds that a user-level process named 'notepad.exe' has spawned a child process named 'cmd.exe', which then created a scheduled task named 'MicrosoftEdgeUpdateTaskMachineUA' that runs a PowerShell script from the user's AppData folder. The analyst suspects a fileless malware infection. Which of the following techniques is the malware MOST likely using to maintain persistence?

Hard
13

A security engineer is hardening a fleet of Windows servers that run a legacy business application. The application vendor requires that the servers retain the ability to run unsigned macros for compatibility. Which mitigation strategy best reduces the risk of malicious macro-based code execution while maintaining the application's required functionality?

Hard
14

A penetration tester is examining a Windows 10 system and discovers that a recent exploit leveraged a use-after-free vulnerability in a widely used PDF reader application. The exploit successfully achieved code execution. Which of the following mitigation technologies, when enabled, would have made this exploitation significantly more difficult by randomizing the memory locations of key data structures?

Hard
15

A Linux web server was compromised through a vulnerable PHP application. The attacker uploaded a web shell and is now using it to run commands. An incident responder needs to determine how the attacker is maintaining access after reboots. Which artifact should the responder check first to identify a persistent mechanism on this Linux host?

Medium
16

A security analyst at a financial firm discovers that a user's workstation is executing a malicious macro embedded in a Microsoft Word document. The macro is attempting to download a second-stage payload from a remote server. The analyst wants to prevent this specific type of attack from succeeding on other workstations while allowing legitimate macros to run. Which of the following is the MOST effective mitigation?

Medium

Frequently asked questions

What does the Malicious Code and Exploit Mitigation domain cover on the GSEC exam?
You must identify attacker persistence and choose the strongest mitigation for each scenario: allowlisting for unauthorized execution, memory or behavioral detection for fileless code, and macro or ASR controls for legacy Windows servers. The key is picking deny-by-default and memory-based detection over signature scanning.
How many questions are in this domain?
This page lists all 16 Malicious Code and Exploit Mitigation questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Malicious Code and Exploit Mitigation questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC malicious code and exploit mitigation Practice Questions