
GIAC Defending Advanced Threats
Domain 1Objective 3
Application Exploitation GDAT Practice Questions (Page 8)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
4concepts
Questions 36–40
- 36
A company has a web application that is vulnerable to cross-site scripting (XSS). The development team is implementing a content security policy (CSP) to mitigate the risk. Which of the following is the most important CSP directive to prevent the execution of injected scripts?
Select an answer first - 37
In the context of the MITRE ATT&CK framework, what is the primary role of application exploitation during the Initial Access phase?
Select an answer first - 38
An attacker exploits a buffer overflow in a network service to execute arbitrary code. The service runs with root privileges on a Linux server. Which of the following is the most effective defense-in-depth control to limit the impact of this type of exploitation?
Select an answer first - 39
In the context of exploiting a buffer overflow, what is the purpose of shellcode?
Select an answer first - 40
A company is migrating a legacy web application to a modern platform. The application has a history of XSS vulnerabilities. The security team wants to implement a comprehensive XSS defense. They have limited budget and cannot rewrite the entire front-end. Which approach would provide the MOST effective protection with the least operational overhead?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.