
GIAC Critical Controls Certification
Domain 7Objective 2
Penetration Testing GCCC Practice Questions (Page 9)
Part of the Incident Response and Testing domain, which makes up ~11% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~6–9 in this domain), expect 3–5 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 41–45
- 41
A penetration tester has compromised a workstation and is attempting to move laterally to a database server. The tester discovers that the database server is on a different subnet and is protected by a firewall that only allows traffic from specific IP addresses. What is the most effective way for the tester to proceed?
Select an answer first - 42
What is the primary purpose of a vulnerability scanner?
Select an answer first - 43
Which tool is commonly used for vulnerability scanning?
Select an answer first - 44
Which penetration testing methodology is specifically focused on web application security and provides a testing guide with a set of security controls?
Select an answer first - 45
During a penetration test, a tester has gained initial access to a web server by exploiting a SQL injection vulnerability in a legacy application. The tester's objective is to reach a database server on a separate internal subnet that is not directly accessible from the tester's workstation. The web server has two network interfaces: one connected to the DMZ and one connected to the internal subnet. The tester has a low-privilege shell on the web server. Which technique should the tester use to reach the database server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCCC” is a trademark of its owner, used for identification only.