Courseiva

GSEC · topic practice

Endpoint Security practice questions

GSEC endpoint security covers hardening Windows and Linux hosts, detecting malware that evades disk, and controlling what code may execute. Questions present incident scenarios or policy exhibits and ask you to choose the correct forensic artifact, Group Policy or AppLocker outcome, or layered control, so you must know native tools and their actual behavior.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Endpoint Security

What the exam tests

What to know about Endpoint Security

Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.

Memory analysis with Volatility or similar tools to find injected, file-less malware in RAM

AppLocker and Software Restriction Policies rules governing execution from user-writable paths like AppData

Windows Defender Application Control and driver signing enforcement for kernel-mode code integrity

Defense-in-depth ransomware controls: patching, least privilege, backups, EDR, and network segmentation

Watch out for

Common Endpoint Security exam traps

  • ▸Assuming antivirus file scanning detects file-less malware; only memory or behavioral analysis reveals code living solely in RAM.
  • ▸Believing AppLocker default rules allow execution from AppData; user-writable paths are commonly blocked by path or publisher rules.
  • ▸Confusing driver signature enforcement with Secure Boot or HVCI; each blocks different unsigned or tampered kernel code paths.

Practice set

Endpoint Security questions

20 questions · select your answer, then reveal the explanation

An administrator observes unauthorized lateral movement via PowerShell Remoting on a Windows network. Which security control best mitigates this risk by restricting administrative access to specific jump hosts?

An organization is deploying an Endpoint Detection and Response (EDR) solution. Which TWO of the following capabilities are primarily focused on post-compromise detection and investigation?

Which configuration best protects an endpoint against 'Pass-the-Hash' (PtH) attacks involving local administrator accounts?

A security analyst is investigating a Windows 10 workstation that has been compromised by a fileless malware attack. The malware executed entirely in memory and left no files on disk, but the analyst suspects the malicious code was injected into a legitimate process. Which native Windows feature should the analyst examine to identify the injected code and its origin?

A financial institution is hardening its Linux servers against privilege escalation attacks. The security team wants to enforce that only binaries with a valid digital signature from approved vendors can execute with elevated privileges, while allowing unsigned binaries to run with normal user permissions. Which Linux kernel feature should the team implement to achieve this granular control?

A security analyst is investigating a compromised Linux server. The attacker gained initial access via a web application vulnerability and then escalated privileges to root. The analyst needs to determine what persistence mechanisms were installed. Which of the following locations should the analyst examine FIRST to identify a malicious cron job that runs every minute?

A security analyst is hardening a fleet of Windows 10 workstations that must run only approved business applications. The analyst wants to block all unapproved executables and scripts, including those launched by users with local administrator rights, while minimizing disruption to signed Microsoft and third-party applications. Which Windows feature should the analyst implement?

Refer to the exhibit. An administrator applies this policy to a Windows workstation. What is the expected behavior for a user attempting to execute a legitimate application installed in their AppData folder?

Exhibit

{"Policy": "ApplicationControl", "Mode": "Enforce", "Rules": [{"Action": "Allow", "Path": "C:\\Program Files\\*"}, {"Action": "Deny", "Path": "C:\\Users\\*\\AppData\\*"}]}

Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?

When configuring endpoint security, which THREE of the following are considered 'defense-in-depth' measures to protect against ransomware?

An incident responder notices suspicious memory usage on a protected host. Which endpoint forensic technique is most reliable for detecting file-less malware that resides only in RAM?

Question 12mediummultiple choice
Read the full Endpoint Security explanation →

When evaluating an endpoint's disk encryption, why is 'Pre-Boot Authentication' (PBA) considered a critical security component?

Question 13mediummultiple choice
Read the full Endpoint Security explanation →

A Windows 10 workstation in a high-security environment must be configured so that only digitally signed and approved kernel-mode drivers can load, blocking unsigned or tampered drivers that could be used for rootkit installation. Which Windows feature should the administrator enable to enforce this requirement?

A security administrator is hardening a fleet of Windows 10 endpoints against credential theft attacks such as Pass-the-Hash and credential dumping. Which TWO of the following measures directly mitigate these threats by protecting credentials in memory and restricting their use? (Choose two.)

A security team wants to implement application whitelisting on a set of Windows 10 workstations to prevent users from running unauthorized executables. They need a solution that integrates with Group Policy and allows rules based on file path, hash, or publisher. Which built-in Windows feature should they use?

Question 16mediummultiple choice
Read the full Endpoint Security explanation →

A security analyst is reviewing a Windows endpoint that is suspected to be compromised with a fileless malware infection. The malware is believed to have injected malicious code into a legitimate process. Which Windows tool should the analyst use to inspect the memory of running processes for signs of injection?

A healthcare provider must protect laptops that store electronic protected health information (ePHI). The security team wants to ensure that if a laptop is lost or stolen, the data on the drive remains confidential even if an attacker removes the drive and connects it to another computer. The team also wants to minimize the risk of cold-boot attacks that could extract encryption keys from memory. Which full disk encryption configuration best meets these requirements?

A small business wants to protect its Windows endpoints from malware delivered through email attachments and malicious websites. The owner asks a security consultant for a single built-in Windows feature that can provide real-time antivirus scanning, cloud-based protection, and automatic updates without purchasing third-party software. Which Windows feature should the consultant recommend?

A security team is investigating a compromised Linux server. The attacker gained initial access through a web application and then established persistence. The team wants to identify the mechanism used to maintain access across reboots. Which Linux artifact should the team examine first to find scheduled tasks that run automatically?

A security administrator is implementing endpoint hardening on a fleet of Windows 10 laptops. The administrator wants to reduce the attack surface by disabling or restricting features that are commonly abused by attackers. Which TWO of the following actions are appropriate endpoint hardening measures? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Endpoint Security sessions

Start a Endpoint Security only practice session

Every question in these sessions is drawn from the Endpoint Security domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Endpoint Security?
Be able to pick the right endpoint forensic technique for memory-resident threats, predict AppLocker or SRP policy outcomes for user-writable folders, and select layered ransomware defenses. The key is knowing which native Windows or Linux control actually blocks the described execution.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Endpoint Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Endpoint Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.