Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 4Objective 2

Penetration Testing Application GCED Practice Questions (Page 2)

Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 6–10

  1. 6application · medium

    During an internal penetration test, a tester discovers a web application that uses a custom login form. The tester has already enumerated valid usernames through a password reset feature. The tester wants to identify whether the application is vulnerable to SQL injection in the username field without causing a denial of service. Which technique is most appropriate?

    Select an answer first
  2. 7application · medium

    A penetration testing team has completed an engagement and is writing the final report. The client's management wants a clear understanding of which vulnerabilities pose the greatest risk to the business. The report must also provide actionable steps for remediation. Which approach best meets these requirements?

    Select an answer first
  3. 8application · medium

    A security analyst is asked to determine whether a newly discovered vulnerability in a web server can be exploited to gain unauthorized access. The analyst has already run a vulnerability scanner that confirmed the vulnerability exists. What is the next step to assess the actual risk?

    Select an answer first
  4. 9application · medium

    A penetration tester has identified a remote code execution vulnerability in a web application. The tester wants to demonstrate the impact by gaining a foothold on the server. Which technique is most appropriate?

    Select an answer first
  5. 10expert · hard

    A penetration tester is assessing a large network and has identified several potential vulnerabilities using an automated scanner. The tester needs to prioritize which vulnerabilities to exploit first. The client's primary concern is preventing a data breach. Which factor should the tester prioritize?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.