Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 1Objective 3

Application Exploitation GDAT Practice Questions (Page 2)

Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 6–10

  1. 6application · medium

    A company is developing a new web application and wants to implement security controls from the start. The development team is considering various approaches to prevent SQL injection. Which of the following is the most effective and recommended practice?

    Select an answer first
  2. 7application · medium

    A security analyst is investigating a suspicious document that was emailed to an employee. The document contains a macro that, when enabled, downloads and executes a payload from a remote server. Which of the following best describes the exploitation technique used in this scenario?

    Select an answer first
  3. 8application · medium

    An organization runs a critical legacy application that is no longer patched by the vendor. The application is exposed to the internet and has a known buffer overflow vulnerability. The security team must reduce the risk of exploitation while the application is being replaced. Which of the following controls is the most effective to implement immediately?

    Select an answer first
  4. 9expert · hard

    A security team is analyzing a malware infection on a user's workstation. The initial infection vector was a malicious attachment in a phishing email. The attachment exploited a buffer overflow in the email client to execute code. Which of the following best describes the exploitation technique?

    Select an answer first
  5. 10application · medium

    A security analyst is reviewing an incident where an attacker gained initial access to a corporate network. The attacker exploited a vulnerability in a web application to upload a web shell, then used that shell to execute commands on the server. Which of the following best describes the role of application exploitation in this attack chain?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.