Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Critical Controls Certification

Domain 7Objective 2

Penetration Testing GCCC Practice Questions (Page 5)

Part of the Incident Response and Testing domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 21–25

  1. 21application · medium

    A company is planning a penetration test of its internal network. The compliance team requires that the test not disrupt business operations during working hours. The security team has proposed a test window from 2 AM to 6 AM on a weekend. Which factor is most important to include in the test scope to ensure the test stays within this constraint?

    Select an answer first
  2. 22expert · hard

    A penetration tester is planning an assessment of a large enterprise network. The client has requested that the test be as stealthy as possible to avoid alerting the security operations center (SOC). The tester must balance the need for thorough coverage with the constraint of avoiding detection. Which approach best balances these competing requirements?

    Select an answer first
  3. 23application · medium

    A security team is conducting a vulnerability assessment of a new web application. They have run an automated scanner and found several potential issues. The team wants to prioritize the findings for remediation. Which factor should be the primary consideration when prioritizing?

    Select an answer first
  4. 24application · medium

    A penetration tester is assigned to assess the external perimeter of a company. The client has approved active scanning of their public IP ranges but has explicitly prohibited any exploitation attempts. The tester begins by querying DNS records, reviewing SSL certificate transparency logs, and searching public code repositories for exposed credentials. After this, the tester runs a credentialed vulnerability scan against the approved targets. Which phase of the penetration testing methodology does the tester's initial information-gathering activity represent?

    Select an answer first
  5. 25expert · hard

    During a penetration test, a tester has gained access to a Linux server by exploiting a vulnerable web application. The tester has a low-privilege user account. The tester discovers that the server has a cron job running as root that executes a script in a directory where the tester has write permissions. Which post-exploitation technique should the tester use to escalate privileges?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.