
GIAC Certified Enterprise Defender
Domain 4Objective 2
Penetration Testing Application GCED Practice Questions (Page 7)
Part of the Penetration Testing domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 31–35
- 31
A penetration tester has exploited a vulnerability in a web application and gained access to the underlying server. The tester's objective is to maintain access for further testing, but the client has strict rules of engagement that prohibit the use of malware. Which technique is most appropriate?
Select an answer first - 32
What is the purpose of risk assessment in a penetration testing report?
Select an answer first - 33
A security team has been asked to assess the security posture of a new web application. The team has already run a vulnerability scanner that reported several potential issues. The team wants to confirm which issues are actually exploitable and understand the business impact. What should the team do?
Select an answer first - 34
A penetration tester is assessing a network and has identified an open port on a server. The tester needs to determine which service is running and whether it has known vulnerabilities. Which technique is most appropriate for this task?
Select an answer first - 35
Which of the following is an example of an exploitation technique?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCED” is a trademark of its owner, used for identification only.