Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 1Objective 3

Application Exploitation GDAT Practice Questions (Page 5)

Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
4concepts

Questions 21–25

  1. 21expert · hard

    A security architect is designing a defense strategy for a web application that processes untrusted user input. The application is written in a language that is not memory-safe, and the team has a history of buffer overflow vulnerabilities. The architect wants to implement a control that will prevent exploitation even if a buffer overflow is present. Which control would be MOST effective?

    Select an answer first
  2. 22application · medium

    A security analyst is documenting an attack chain. The attacker exploited a buffer overflow in a public-facing service to gain a foothold, then used that access to move laterally and eventually compromise domain controllers. At which phase of the attack lifecycle did application exploitation occur?

    Select an answer first
  3. 23application · medium

    A security analyst is investigating a server that was compromised. The analyst finds a process running with elevated privileges that was spawned from a buffer overflow in a legacy network service. The attacker's payload appears to have executed shellcode that called a function to spawn an interactive shell. Which exploitation technique is described?

    Select an answer first
  4. 24application · medium

    A penetration tester is exploiting a web application vulnerability. The tester sends a request that includes a payload in a URL parameter. The application reflects the parameter value in the response without encoding. The tester then crafts a link that, when clicked by an administrator, executes JavaScript in the admin's browser session. Which exploitation technique is being used?

    Select an answer first
  5. 25application · medium

    A developer is writing a web application that allows users to upload profile pictures. The application stores the files in a public directory and later displays them. Which of the following is the most important control to prevent an attacker from uploading a malicious executable that could be executed on the server?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.