
GIAC Certified Enterprise Defender
Domain 4Objective 2
Penetration Testing Application GCED Practice Questions (Page 3)
Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 11–15
- 11
What is lateral movement in the context of post-exploitation?
Select an answer first - 12
After completing a penetration test, the tester must present findings to both technical staff and executives. The technical staff need detailed remediation steps, while executives need a high-level risk summary. What is the best way to structure the report?
Select an answer first - 13
What is the primary purpose of the remediation recommendations in a penetration testing report?
Select an answer first - 14
A penetration tester has completed an assessment and identified a critical vulnerability in a customer's application. The customer's management is concerned about the business impact and wants to understand the risk in financial terms. Which approach should the tester take in the report?
Select an answer first - 15
A penetration tester is planning an engagement for a client that wants to test its web application's resistance to common attacks. The client has a limited budget and wants to focus on the OWASP Top 10. Which methodology is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.