Free GIAC Security Essentials practice — 6 questions on Endpoint Security and Malicious Code, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Endpoint Security and Malicious Code
A threat actor gains initial access to a Windows workstation and executes a PowerShell script directly in memory that never writes an executable file to disk. The script uses WMI event subscriptions for persistence. Which endpoint control would BEST detect and prevent this attack?
AMSI inspects script content at runtime as it executes in memory, regardless of whether a file ever touches disk, and Constrained Language Mode restricts access to dangerous .NET/COM APIs that fileless attacks rely on. Script Block Logging captures the deobfuscated command for analysis.
Question 2 of 6 · Endpoint Security and Malicious Code
Which anti-malware detection technique is specifically designed to identify process hollowing, where malicious code replaces the memory of a legitimate suspended process rather than modifying the on-disk executable?
Process hollowing manipulates memory at runtime while the on-disk binary and its launching process remain legitimate, so only behavioral/heuristic monitoring of the API sequence (create suspended -> NtUnmapViewOfSection -> WriteProcessMemory -> ResumeThread) can reliably catch it.
Question 3 of 6 · Endpoint Security and Malicious Code
An organization implements AppLocker to prevent unauthorized executables. Which AppLocker rule type provides the STRONGEST protection against an attacker who renames a malicious executable to match a permitted filename in an allowed path?
A hash rule ties the allow decision to the exact cryptographic hash of the permitted binary's contents. Renaming a malicious file to match an allowed filename does not change its hash, so it still fails to match and is blocked — regardless of name or location.
Question 4 of 6 · Endpoint Security and Malicious Code
How does metamorphic malware differ from polymorphic malware in the way each evades signature-based detection?
Polymorphic malware re-encrypts identical malicious logic with a new key/decryptor each time, so the decrypted payload is constant even though the encrypted wrapper varies. Metamorphic malware actually rewrites and reorders its own code on each propagation, producing functionally equivalent but structurally different code with no fixed decryptor to signature on.
Question 5 of 6 · Endpoint Security and Malicious Code
During incident response, an analyst suspects a rootkit is hiding malicious processes from Task Manager and the standard Windows API. Which technique should the analyst use to detect the discrepancy?
Cross-view detection compares what a high-level tool using the standard API reports against what a low-level tool reading raw memory or disk structures reports. A rootkit that hooks the API to hide a process will produce a mismatch between the two views, exposing its presence.
Question 6 of 6 · Endpoint Security and Malicious Code
A security team wants to block Microsoft Office applications from spawning child processes such as PowerShell or cmd.exe, a common technique used by macro-based malware. Which Windows Defender feature should be configured to enforce this specific behavioral restriction?
This exact behavior is what the named ASR rule is built for: it proactively blocks the specific parent-child process relationship (Office spawning a shell or scripting host) regardless of whether the payload is a known signature.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.