Courseiva
Endpoint Security →mediumMultiple Choice

GSEC Endpoint Security Practice Question

Which endpoint hardening technique is most effective at preventing unauthorized code execution by restricting the environment to only pre-approved software?

⚠ Common exam trap

Examinees often select traditional antivirus or signature-based detection tools, missing that allowlisting is uniquely required to block *all* unauthorized code by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing an application allowlisting solution.

Allowlisting, or application control, is the most robust method for preventing unknown or unauthorized code execution. By only allowing known, trusted binaries to run, it mitigates the risk of malware, even zero-day exploits, since the malicious code will not be on the approved list. This is a foundational strategy for high-security environments where the risk of execution must be strictly minimized.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disabling local administrator accounts for standard users.

    Why it's wrong here

    While removing local admin rights is a critical security best practice, it does not prevent a user from executing malicious code within their own user space. An attacker could still run malware that does not require elevated privileges, such as file-less scripts or standard user-level backdoors.

  • ✓

    Implementing an application allowlisting solution.

    Why this is correct

    Allowlisting works by creating a whitelist of authorized applications. Any file not on this list is blocked by the OS or agent. This effectively stops unauthorized software, scripts, and malware from running, providing a much stronger security posture than traditional antivirus, which relies on identifying known bad files.

  • ✗

    Enabling real-time scanning in antivirus software.

    Why it's wrong here

    Antivirus software relies on signatures or heuristics to detect malware. It is inherently reactive and can be bypassed by new or obfuscated threats. While necessary for general defense, it cannot provide the same level of assurance as an allowlisting policy, which restricts execution to known-good binaries only.

  • ✗

    Configuring the firewall to block all inbound traffic.

    Why it's wrong here

    Blocking inbound traffic prevents external attackers from reaching the machine, but it does not protect against malware introduced via phishing, physical media, or browser-based attacks. Execution control is a local endpoint issue that requires specific software-level restriction policies, not just network-level filtering to block unsolicited connections.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.