
GIAC Certified Enterprise Defender
Domain 4Objective 2
Penetration Testing Application GCED Practice Questions (Page 6)
Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 26–30
- 26
A penetration tester is assessing a web application that uses a WAF. The tester has identified a potential SQL injection but the WAF is blocking common attack payloads. The tester needs to confirm the vulnerability without triggering a block that could alert the client. Which technique is most appropriate?
Select an answer first - 27
A penetration tester is contracted to assess the external perimeter of a financial services company. The client has provided a scope document listing only the company's public IP ranges and domain names, but explicitly forbids any active scanning that could trigger the IDS/IPS before the testing window begins. The tester needs to build an initial profile of the target's technology stack and employee behaviors. Which approach best fits the constraint?
Select an answer first - 28
A penetration tester has gained access to a domain-joined Windows workstation with a standard user account. The tester's objective is to access a file server that requires domain administrator privileges. The tester has identified a service running with SYSTEM privileges that has a known privilege escalation vulnerability. What should the tester do?
Select an answer first - 29
A penetration tester has gained access to a Windows server as a low-privileged user. The tester's objective is to escalate privileges to domain administrator. Which post-exploitation technique is most appropriate?
Select an answer first - 30
A security manager wants to understand the difference between a vulnerability scan and a penetration test to decide which to conduct. The manager's primary concern is identifying exploitable vulnerabilities that could lead to a data breach. Which statement accurately describes the key difference?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.