
GIAC Defending Advanced Threats
Domain 1Objective 3
Application Exploitation GDAT Practice Questions (Page 7)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 31–35
- 31
A company is deploying a new web application and wants to implement a defense-in-depth strategy against application exploitation. The application will handle sensitive data and must be highly available. Which of the following is the most comprehensive approach?
Select an answer first - 32
During a penetration test, an analyst discovers that a legacy web application reflects user input in an error message without proper encoding. The analyst wants to demonstrate a realistic attack that could steal a victim's session cookie. Which of the following exploitation techniques is most appropriate?
Select an answer first - 33
A penetration tester is attempting to exploit a web application that uses a strict Content Security Policy (CSP) that disallows inline scripts and only allows scripts from the application's own domain. The tester finds a DOM-based XSS vulnerability that injects data into the page. Which technique would be MOST likely to bypass the CSP and execute JavaScript?
Select an answer first - 34
Which vulnerability class involves an attacker injecting malicious client-side scripts into web pages that are then executed by other users' browsers?
Select an answer first - 35
A security architect is reviewing a web application that handles sensitive data. The application is built with a modern framework that uses parameterized queries for all database access. However, a legacy module still concatenates user input directly into SQL statements. The team cannot remove the legacy module immediately. Which combination of controls would provide the BEST defense-in-depth while the legacy module is being rewritten?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.