Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 4Objective 1

Automating Offensive Workflows GASAE Practice Questions (Page 2)

Part of the Offensive and Defensive Automation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
8concepts

Questions 6–10

  1. 6expert · hard

    A security team is integrating a custom exploit tool with a commercial C2 framework. The exploit tool outputs data in a custom binary format, and the C2 framework expects JSON over HTTP. The team needs to automate the transfer of data from the exploit tool to the C2 framework, but the exploit tool cannot be modified. What is the best approach?

    Select an answer first
  2. 7application · medium

    An automated offensive workflow includes a long-running vulnerability scan that must complete before exploitation begins. The scan sometimes fails due to network timeouts. The team wants to ensure that the exploitation phase only starts after a successful scan, and that the workflow does not hang indefinitely. Which configuration is most appropriate?

    Select an answer first
  3. 8expert · hard

    A red team is automating a post-exploitation workflow that includes data collection from a database. The client has a strict policy that prohibits copying production data to any external system, even for testing. The team needs to demonstrate the ability to extract sensitive data, but must comply with the policy. What is the best way to achieve this?

    Select an answer first
  4. 9expert · hard

    A penetration testing team is automating exploitation of a web application that uses a Web Application Firewall (WAF). The team's exploit scripts are being blocked by the WAF. They need to adjust the automation to bypass the WAF while staying within the rules of engagement. Which approach is most appropriate?

    Select an answer first
  5. 10expert · hard

    A red team is automating a post-exploitation workflow that includes data exfiltration from a client's environment. The client has strict data protection policies and requires that no data leaves the production network. The team must still demonstrate the ability to exfiltrate data. What is the best way to satisfy both the client's policy and the exercise objective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.