
GIAC AI Security Automation Engineer
Domain 4Objective 1
Automating Offensive Workflows GASAE Practice Questions (Page 3)
Part of the Offensive and Defensive Automation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 8–13 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 11–15
- 11
An automated post-exploitation pipeline must perform privilege escalation, lateral movement, and data exfiltration across a Windows domain. The team requires that the pipeline minimize the chance of triggering endpoint detection and response (EDR) alerts, and also requires that if a lateral movement step fails, the pipeline retries with a different technique before aborting. Which design best meets these constraints?
Select an answer first - 12
A security team is integrating a commercial vulnerability scanner with an open-source exploitation framework. The scanner outputs findings in a proprietary format, and the exploitation framework expects a specific XML schema. The team needs to automate the transfer of findings from the scanner to the exploitation framework, but the scanner's API is rate-limited and the exploitation framework cannot be modified. What is the most effective approach?
Select an answer first - 13
A penetration tester needs to automate service enumeration across a large IP range. The tester wants to identify open ports and running services, and then feed that information into a vulnerability scanner. Which approach is most efficient?
Select an answer first - 14
A red team needs to automate OSINT gathering for a client. The team wants to collect data from public sources such as social media, job postings, and DNS records, and then correlate this data to identify potential usernames and technologies. The automation must respect rate limits and legal boundaries. Which toolset and approach is most appropriate?
Select an answer first - 15
Which of the following is an orchestration platform commonly used to automate offensive security workflows?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.