
GIAC Defending Advanced Threats
Domain 1Objective 3
Application Exploitation GDAT Practice Questions (Page 5)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 21–25
- 21
A security architect is designing a defense strategy for a web application that processes untrusted user input. The application is written in a language that is not memory-safe, and the team has a history of buffer overflow vulnerabilities. The architect wants to implement a control that will prevent exploitation even if a buffer overflow is present. Which control would be MOST effective?
Select an answer first - 22
A security analyst is documenting an attack chain. The attacker exploited a buffer overflow in a public-facing service to gain a foothold, then used that access to move laterally and eventually compromise domain controllers. At which phase of the attack lifecycle did application exploitation occur?
Select an answer first - 23
A security analyst is investigating a server that was compromised. The analyst finds a process running with elevated privileges that was spawned from a buffer overflow in a legacy network service. The attacker's payload appears to have executed shellcode that called a function to spawn an interactive shell. Which exploitation technique is described?
Select an answer first - 24
A penetration tester is exploiting a web application vulnerability. The tester sends a request that includes a payload in a URL parameter. The application reflects the parameter value in the response without encoding. The tester then crafts a link that, when clicked by an administrator, executes JavaScript in the admin's browser session. Which exploitation technique is being used?
Select an answer first - 25
A developer is writing a web application that allows users to upload profile pictures. The application stores the files in a public directory and later displays them. Which of the following is the most important control to prevent an attacker from uploading a malicious executable that could be executed on the server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.