Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 4Objective 1

Data Exfiltration GDAT Practice Questions (Page 1)

Part of the Exfiltration and Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)

45questions here
9free pages
4concepts

Questions 1–5

  1. 1foundation · easy

    Which action is essential for preserving evidence during a data exfiltration response?

    Select an answer first
  2. 2application · medium

    A security analyst is reviewing network logs and notices a series of HTTP POST requests from an internal server to an external IP address. The POST bodies are unusually large and occur at regular intervals. The server is not supposed to communicate with that IP. What does this pattern most likely indicate?

    Select an answer first
  3. 3expert · hard

    An incident response team is handling a data exfiltration incident where the attacker used a previously unknown malware variant. The team has identified the command-and-control (C2) server and has the ability to block it. However, blocking the C2 server may alert the attacker and cause them to destroy evidence on compromised systems. What is the best approach?

    Select an answer first
  4. 4expert · hard

    A security analyst is reviewing network traffic and notices that a server is sending a large amount of data to an external IP using a protocol that is normally used for network management. The traffic is occurring at regular intervals and the data size is consistent. The server is not supposed to send data to that IP. What is the most likely explanation?

    Select an answer first
  5. 5application · medium

    A security analyst sees a workstation sending HTTP POST requests to a website that hosts images. The POST requests contain image files, but the images appear to have slightly altered pixel data. The analyst suspects steganography. Which detection method would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.