
GIAC Defending Advanced Threats
Domain 1Objective 3
Application Exploitation GDAT Practice Questions (Page 6)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 26–30
- 26
A security analyst is investigating a series of attacks against a web application. The application uses a NoSQL database. The analyst notices that the application is vulnerable to injection attacks that manipulate database queries by sending JSON objects with special operators like $gt and $ne. Which vulnerability class is being exploited?
Select an answer first - 27
Which defense strategy is most directly effective in preventing SQL injection attacks?
Select an answer first - 28
A security team is responding to an incident where an attacker exploited a SQL injection vulnerability in a public-facing web application. The application is business-critical and cannot be taken offline. The team has identified the vulnerable query and is considering immediate mitigation options. Which of the following is the most appropriate immediate action?
Select an answer first - 29
A security analyst is reviewing a vulnerability scan report for a web application. The report indicates that the application is vulnerable to cross-site scripting (XSS) in a search field. The analyst wants to confirm the vulnerability and assess the impact. Which of the following is the most appropriate next step?
Select an answer first - 30
Which vulnerability class is characterized by an application using unsanitized user input to construct an operating system command that is then executed by the server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.