Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Certified Enterprise Defender

Domain 4Objective 2

Penetration Testing Application GCED Practice Questions (Page 5)

Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)

47questions here
10free pages
7concepts

Questions 21–25

  1. 21application · medium

    A company wants to assess the security of its custom web application before a major release. The security team has limited time and budget, and the application is already in production. The team needs to identify exploitable vulnerabilities in the application's business logic and input handling. Which methodology is most appropriate?

    Select an answer first
  2. 22foundation · easy

    Which of the following is an example of passive reconnaissance?

    Select an answer first
  3. 23foundation · easy

    What is the primary goal of a penetration test compared to a vulnerability scan?

    Select an answer first
  4. 24foundation · easy

    Which technique is considered active reconnaissance?

    Select an answer first
  5. 25application · medium

    During a penetration test, a tester finds that a web application is vulnerable to SQL injection in the search parameter. The tester wants to demonstrate the impact by retrieving data from the database. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.