Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 7Objective 2

Penetration Testing GCCC Practice Questions (Page 2)

Part of the Incident Response and Testing domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 6–10

  1. 6foundation · easy

    What is a key component of a penetration testing report?

    Select an answer first
  2. 7application · medium

    A penetration test has concluded, and the tester is writing the final report. The report includes a finding for a critical remote code execution vulnerability in an internet-facing application. The client's IT team has asked for enough detail to reproduce the issue during remediation verification. Which element should the tester include in the report to satisfy this request while maintaining professional standards?

    Select an answer first
  3. 8application · medium

    A penetration tester is using a vulnerability scanner to assess a network. The scanner reports a critical vulnerability in a web server. Before including this finding in the report, what should the tester do to ensure accuracy?

    Select an answer first
  4. 9expert · hard

    A penetration tester has successfully exploited a vulnerability in a Windows server and gained a low-privilege shell. The tester's goal is to move laterally to a domain controller. The tester finds that the current user has local administrator rights on the server but not domain admin rights. The tester also discovers that a service account with domain admin privileges is running on the server. Which post-exploitation technique would be most effective to achieve the goal?

    Select an answer first
  5. 10expert · hard

    A penetration tester is assessing a web application that uses a content management system (CMS). The tester has identified a known remote code execution vulnerability in the CMS version, but the vulnerability requires authentication as an editor-level user. The tester has a valid editor account. The tester's goal is to gain a foothold on the underlying server. Which approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.