GSEC Windows Automation and Auditing Practice Question
You are hardening a Windows environment and must restrict the use of PowerShell to only digitally signed scripts. Which command should you execute?
⚠ Common exam trap
Candidates often confuse 'AllSigned' with 'RemoteSigned'. 'AllSigned' requires every script to be signed, whereas 'RemoteSigned' only requires signatures for scripts downloaded from the internet, making it less restrictive.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set-ExecutionPolicy AllSigned
Setting the execution policy to 'AllSigned' forces the system to verify that every script has been signed by a trusted publisher. This is a fundamental security control that prevents the execution of unauthorized or tampered scripts. Implementing this policy significantly reduces the attack surface for fileless malware that relies on unconstrained execution of PowerShell commands and scripts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set-ExecutionPolicy RemoteSigned
Why it's wrong here
RemoteSigned allows scripts created locally to run unsigned, while only downloaded scripts require a signature. This is less secure than AllSigned, as it leaves the system vulnerable to locally staged scripts that an attacker might drop onto the disk.
- ✓
Set-ExecutionPolicy AllSigned
Why this is correct
The AllSigned policy mandates that all scripts, including local ones, must be digitally signed by a trusted publisher. This is the recommended security posture for preventing unauthorized script execution and ensuring integrity, making it a critical hardening step for any secure environment.
- ✗
Set-ExecutionPolicy Unrestricted
Why it's wrong here
Unrestricted allows all scripts to run without any verification. This is a highly dangerous configuration that nullifies the security benefits of the PowerShell execution policy, leaving the machine entirely exposed to arbitrary script execution by local or remote attackers.
- ✗
Set-ExecutionPolicy Bypass
Why it's wrong here
Bypass removes all restrictions, effectively disabling the security policy of PowerShell. This is used only for testing and should never be implemented in a production environment, as it invites security compromises through unverified and potentially malicious script execution.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.