Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Cloud Penetration Tester

Domain 6Objective 2

Redirection and Attack Obfuscation GCPN Practice Questions (Page 4)

Part of the Credential Attacks and Evasion domain, which makes up ~15% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 4–6 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    What is the primary purpose of using a redirect chain (multiple sequential redirects) in an attack payload?

    Select an answer first
  2. 17application · medium

    You are designing a phishing campaign that uses a redirection chain to evade detection. The chain must be resilient to URL reputation services that block known malicious domains. Which chain design is most effective?

    Select an answer first
  3. 18application · medium

    You are developing a credential-harvesting tool that must evade antivirus detection on the victim's machine. The tool downloads a payload from a remote server and executes it in memory. Which obfuscation approach is most effective for evading signature-based antivirus?

    Select an answer first
  4. 19foundation · easy

    What is the primary purpose of attack obfuscation in the context of credential attacks?

    Select an answer first
  5. 20foundation · easy

    Which of the following is an example of attack obfuscation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GCPN” is a trademark of its owner, used for identification only.