Courseiva

CCNA Endpoint Security Questions

13 questions · Endpoint Security topic · All types, answers revealed

1
Multi-Selectmedium

A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)

Select 2 answers
A.Enable Credential Guard
B.Enable BitLocker with TPM
C.Configure LSA protection
D.Enforce SMB signing
E.Deploy Windows Defender Firewall with domain profile
AnswersA, C

Credential Guard uses virtualization-based security to isolate and protect derived domain credentials, such as NTLM hashes and Kerberos tickets, from being extracted by malware. It prevents pass-the-hash attacks by keeping these secrets in a secure container. This directly addresses credential theft and is a correct measure.

Why this answer

Credential Guard and LSA protection directly protect credentials in memory. Credential Guard isolates derived credentials using virtualization-based security, preventing their theft. LSA protection blocks non-PPL processes from reading LSA memory, thwarting credential dumping tools.

SMB signing, Windows Defender Firewall, and BitLocker address other security aspects but do not directly prevent credential theft from memory.

Exam trap

The trap here is selecting network or disk encryption controls that seem security-related but do not address in-memory credential protection.

2
MCQmedium

Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?

A.Disabling local administrator accounts for standard users.
B.Implementing an application allowlisting solution.
C.Enabling real-time scanning in antivirus software.
D.Configuring the firewall to block all inbound traffic.
AnswerB

Allowlisting works by creating a whitelist of authorized applications. Any file not on this list is blocked by the OS or agent. This effectively stops unauthorized software, scripts, and malware from running, providing a much stronger security posture than traditional antivirus, which relies on identifying known bad files.

Why this answer

Allowlisting, or application control, is the most robust method for preventing unknown or unauthorized code execution. By only allowing known, trusted binaries to run, it mitigates the risk of malware, even zero-day exploits, since the malicious code will not be on the approved list. This is a foundational strategy for high-security environments where the risk of execution must be strictly minimized.

Exam trap

Examinees often select traditional antivirus or signature-based detection tools, missing that allowlisting is uniquely required to block *all* unauthorized code by default.

3
MCQmedium

A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?

A.Windows Defender Firewall with Advanced Security
B.BitLocker with TPM and PIN
C.AppLocker with default rules
D.Device Guard with Code Integrity policies
AnswerD

Device Guard (now part of Windows Defender Application Control) uses Code Integrity policies to enforce that only trusted, signed kernel-mode drivers and user-mode binaries can execute. It blocks unsigned or malicious drivers from loading, directly preventing rootkit installation. This is the correct choice because it specifically controls driver signing and integrity at the kernel level, meeting the requirement to allow only approved drivers.

Why this answer

Device Guard with Code Integrity policies enforces that only trusted, signed kernel-mode drivers can load, directly preventing unsigned or tampered drivers from being used for rootkits. BitLocker, AppLocker, and Windows Defender Firewall address different security concerns—data encryption, application control, and network filtering—and do not provide kernel-mode driver integrity enforcement. Therefore, Device Guard is the correct solution.

Exam trap

The trap here is confusing application control mechanisms like AppLocker with kernel-mode driver integrity enforcement, which requires a Code Integrity policy under Device Guard.

4
MCQmedium

A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?

A.Resource Monitor
B.Process Explorer
C.Task Manager
D.Event Viewer
AnswerB

Process Explorer is a Sysinternals tool that provides detailed information about running processes, including loaded DLLs, handles, and memory usage. It can show suspicious strings or unsigned modules in process memory, helping detect code injection. This makes it suitable for inspecting process memory for signs of fileless malware. Therefore, it is the correct choice.

Why this answer

Process Explorer provides in-depth process information, including loaded DLLs and memory contents, allowing analysts to spot suspicious or unsigned modules indicative of code injection. Task Manager, Event Viewer, and Resource Monitor lack the ability to inspect process memory in detail. Thus, Process Explorer is the correct tool for this scenario.

Exam trap

The trap here is assuming that built-in tools like Task Manager or Event Viewer can reveal process injection, when they only provide superficial or log-based information.

5
MCQmedium

Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?

A.The application will run normally because AppData is a standard location.
B.The application will be blocked from execution.
C.The application will run, but the activity will be logged for review.
D.The system will automatically move the application to Program Files.
AnswerB

The JSON policy clearly specifies an action of 'Deny' for any file path matching the AppData directory pattern. Because the policy is in 'Enforce' mode, the security agent will block any attempt to execute a binary from this location, effectively stopping the user from running their application.

Why this answer

The policy explicitly defines a 'Deny' rule for the AppData directory. Since the policy mode is set to 'Enforce', the endpoint security engine will block any executable residing in that path. This is a common security practice to prevent the execution of malicious payloads frequently dropped into temporary user directories, though it may inadvertently block legitimate software that installs to the user profile instead of Program Files.

Exam trap

Examinees often assume legitimate software paths bypass security policies, forgetting that explicitly enforced deny rules in application control policies override application legitimacy.

6
MCQeasy

A small business wants to protect its Windows endpoints from malware delivered through email attachments and malicious websites. The owner asks a security consultant for a single built-in Windows feature that can provide real-time antivirus scanning, cloud-based protection, and automatic updates without purchasing third-party software. Which Windows feature should the consultant recommend?

A.BitLocker Drive Encryption
B.Windows Information Protection (WIP)
C.Windows Defender Firewall
D.Microsoft Defender Antivirus
AnswerD

Microsoft Defender Antivirus is the built-in antivirus component of Windows that provides real-time scanning, cloud-delivered protection, and automatic signature updates through Windows Update. It scans files, email attachments, and downloads, and it integrates with Windows Security. It requires no additional purchase and is enabled by default on modern Windows versions, directly matching the consultant's recommendation for a single built-in feature.

Why this answer

Microsoft Defender Antivirus is the correct built-in Windows feature because it delivers real-time antivirus scanning, cloud-based protection, and automatic updates without additional cost. It covers files, email attachments, and web downloads, and it is managed through Windows Security, making it the single feature that satisfies the small business's malware protection needs.

Exam trap

The trap here is confusing Windows Defender Firewall with Microsoft Defender Antivirus because both share the Defender name but serve different security functions.

7
Multi-Selectmedium

When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?

Select 3 answers
A.Applying the Principle of Least Privilege (PoLP) to user file shares.
B.Disabling all network connections to the endpoint.
C.Utilizing offline or immutable backups.
D.Deploying Endpoint Detection and Response (EDR) with behavioral blocking.
E.Enabling guest access for easier file sharing across departments.
AnswersA, C, D

Limiting user permissions ensures that if a workstation is compromised, the attacker can only encrypt the files that user has permission to modify. This prevents the ransomware from spreading to critical shared network drives or sensitive directories, effectively containing the potential impact of the infection to a single user's profile.

Why this answer

Defense-in-depth requires multiple layers of security to ensure that if one control fails, others are present to mitigate the impact. For ransomware, this includes preventing the execution, limiting the scope of damage through permissions, and maintaining immutable backups. These layers ensure that an attacker must overcome multiple, diverse obstacles to achieve their objective of data encryption, significantly increasing the difficulty of a successful attack.

Exam trap

Candidates sometimes select single-layer preventative solutions like basic password policies, missing that defense-in-depth requires multiple complementary layers spanning permissions, detection, and recovery.

8
MCQmedium

When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?

A.It improves the speed of system startup and file indexing.
B.It ensures that the computer cannot be booted from an external drive.
C.It requires authentication before the encryption keys are released to memory.
D.It automatically syncs the encryption keys to a cloud-based backup.
AnswerC

Pre-Boot Authentication forces the user to input a secret before the decryption keys are loaded into RAM. This ensures that the data is truly protected against cold-boot attacks and unauthorized access if the machine is powered off, as the drive remains encrypted until that specific challenge is successfully met.

Why this answer

PBA ensures that the encryption keys are not loaded into memory until the user provides the correct credentials at boot time. Without PBA, the encryption is transparent once the OS starts, meaning if the device is stolen while powered on or in sleep mode, an attacker could potentially access the data. PBA provides a strong gatekeeper that protects the data at rest even before the OS loads.

Exam trap

Candidates often confuse PBA with Full Disk Encryption (FDE) generally, failing to realize that without PBA, the keys are loaded automatically at boot, leaving data vulnerable to cold-boot or memory attacks.

9
Multi-Selectmedium

A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)

Select 2 answers
A.Disable User Account Control (UAC) to improve user productivity
B.Install a second third-party antivirus alongside Microsoft Defender Antivirus
C.Enable the Guest account and assign it a blank password for temporary access
D.Enable PowerShell Constrained Language Mode for all users
E.Disable the Windows Script Host (WSH) to prevent execution of .vbs and .js scripts
AnswersD, E

Constrained Language Mode restricts PowerShell to a limited set of language features and blocks access to arbitrary .NET types and COM objects. This significantly hinders attackers who rely on PowerShell for fileless malware and post-exploitation. Enforcing it for all users is a valid hardening step that reduces the attack surface while still allowing many administrative scripts to run, so it is an appropriate measure.

Why this answer

Disabling Windows Script Host and enforcing PowerShell Constrained Language Mode both reduce the attack surface by limiting common attacker execution techniques. WSH is often abused for script-based malware, and Constrained Language Mode restricts PowerShell's ability to load arbitrary code. Together they harden endpoints without requiring third-party tools, while the other options either weaken security or introduce conflicts.

Exam trap

The trap here is assuming that more security products or user convenience always improve security, when disabling UAC or adding a second antivirus actually increases risk.

10
MCQhard

A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?

A./etc/hosts
B./etc/crontab and the /etc/cron.* directories
C./var/log/auth.log
D./etc/passwd
AnswerB

The /etc/crontab file and the /etc/cron.* directories contain system-wide scheduled tasks that run automatically at specified intervals or at boot. Attackers commonly add entries here to re-establish access after a reboot. Reviewing these locations is a primary step in identifying persistence via scheduled tasks. Other cron locations such as user crontabs also matter, but the system-wide files are the first place to check for reboot-persistent jobs.

Why this answer

System-wide cron files and directories are the primary location for scheduled tasks on Linux. Attackers frequently add entries to /etc/crontab or /etc/cron.* to run malicious commands at boot or regular intervals, ensuring persistence across reboots. Examining these files first aligns with the goal of identifying how the attacker maintains access after a restart.

Exam trap

The trap here is focusing on user account files or logs, when the question specifically asks for scheduled tasks that run automatically.

11
MCQhard

A healthcare provider must protect laptops that store electronic protected health information (ePHI). The security team wants to ensure that if a laptop is lost or stolen, the data on the drive remains confidential even if an attacker removes the drive and connects it to another computer. The team also wants to minimize the risk of cold-boot attacks that could extract encryption keys from memory. Which full disk encryption configuration best meets these requirements?

A.BitLocker with a startup key stored on a USB flash drive
B.BitLocker with TPM and PIN protector, plus pre-boot authentication
C.BitLocker with TPM-only protector and no PIN
D.EFS encryption of the ePHI folders with user certificates
AnswerB

BitLocker with a TPM and PIN protector requires a user-entered PIN before the operating system loads, providing pre-boot authentication. This means an attacker who steals the laptop cannot simply boot it to reach the decryption keys in memory, significantly reducing cold-boot and DMA attack risk. The TPM also seals keys to the platform, so moving the drive to another computer does not allow decryption, meeting the confidentiality requirement.

Why this answer

BitLocker with a TPM and PIN protector enforces pre-boot authentication, so the drive cannot be unlocked without the PIN and the TPM-bound key. This protects against offline drive removal and reduces the window for cold-boot or DMA attacks because the operating system and keys are not loaded until the PIN is entered, satisfying both confidentiality and cold-boot risk reduction.

Exam trap

The trap here is assuming that any BitLocker configuration with a TPM provides pre-boot authentication, when TPM-only mode boots without user input.

12
MCQeasy

A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?

A.Software Restriction Policies (SRP)
B.Windows Defender Application Control (WDAC)
C.AppLocker
D.Windows Defender Firewall
AnswerC

AppLocker is a built-in Windows feature that allows administrators to create rules based on file path, hash, or publisher to control which applications and scripts users can run. It integrates with Group Policy for centralized management. This directly meets the requirement for application whitelisting on Windows 10 workstations. Therefore, AppLocker is the correct choice.

Why this answer

AppLocker is the built-in Windows feature designed for application whitelisting, with rule types based on path, hash, or publisher, and it integrates with Group Policy. WDAC is more complex and less Group Policy-centric, SRP is deprecated, and Windows Defender Firewall does not control application execution. Therefore, AppLocker is the correct solution.

Exam trap

The trap here is confusing AppLocker with WDAC or SRP; while all can restrict applications, AppLocker is the one that best fits the described requirements and is not deprecated.

13
MCQhard

An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?

A.Scanning the hard drive for known malicious file signatures.
B.Analyzing the Master File Table (MFT) for deleted entries.
C.Performing a memory dump and analyzing it for anomalous process threads.
D.Checking the Windows Event Logs for failed login attempts.
AnswerC

Memory forensics tools allow responders to examine the contents of RAM to find injected code, hidden processes, or tampered system calls. By comparing the memory state against a known-good baseline, analysts can identify the specific memory regions used by the file-less malware to maintain its stealthy presence.

Why this answer

File-less malware operates by injecting malicious code directly into the memory space of legitimate system processes. Traditional disk-based scanning tools will miss this, as no malicious file exists on the filesystem. Detecting file-less attacks requires inspecting memory for anomalies, such as injected threads or hooked functions, which requires specialized tools capable of analyzing process memory structures in real-time.

Exam trap

Candidates often select file-based scanning tools or antivirus logs, assuming malware always leaves a footprint on the disk, ignoring that file-less malware executes entirely within volatile memory structures.

Ready to test yourself?

Try a timed practice session using only Endpoint Security questions.