
GIAC Certified Enterprise Defender
Domain 4Objective 2
Penetration Testing Application GCED Practice Questions (Page 4)
Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 16–20
- 16
During an internal penetration test, a tester discovers that a web application's login form does not lock out accounts after multiple failed attempts. The tester wants to confirm this vulnerability and document its impact. Which action should the tester take next?
Select an answer first - 17
A penetration tester has completed an assessment and is writing the final report. The tester needs to ensure that the report is useful for both technical and non-technical stakeholders. Which approach is most appropriate?
Select an answer first - 18
A penetration tester is conducting passive reconnaissance on a target organization. The tester wants to identify employee email addresses and potential technology stacks without directly interacting with the target's systems. Which source is most appropriate for this task?
Select an answer first - 19
In the PTES methodology, which phase follows the 'Threat Modeling' phase?
Select an answer first - 20
Which activity is a distinguishing characteristic of penetration testing as opposed to a vulnerability assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.