
GIAC Defending Advanced Threats
Domain 4Objective 1
Data Exfiltration GDAT Practice Questions (Page 8)
Part of the Exfiltration and Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–15 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
4concepts
Questions 36–40
- 36
A security analyst is investigating a potential data exfiltration incident. The analyst sees a workstation sending data to a remote server using HTTP POST requests, but the data appears to be encrypted and the requests are small and frequent. The analyst also notices that the workstation is sending data to the same server using DNS queries with long subdomains. The analyst has limited time and resources. Which exfiltration technique is most likely being used, and what is the best detection method?
Select an answer first - 37
During an incident, a security analyst discovers that an attacker has been using a legitimate cloud storage service to upload sensitive files from a compromised workstation. The analyst has isolated the workstation. What should the analyst do next to preserve evidence and mitigate further loss?
Select an answer first - 38
A company wants to prevent employees from exfiltrating data via cloud storage services like Dropbox and Google Drive. They have a web proxy that can block categories of websites. Which additional control would be most effective to prevent exfiltration via these services?
Select an answer first - 39
A company is implementing controls to prevent data exfiltration. They have a strict requirement to allow employees to use personal cloud storage for non-sensitive documents, but must prevent sensitive data from being uploaded. They also need to maintain user productivity. Which approach best balances these requirements?
Select an answer first - 40
A security analyst notices that a server is sending outbound ICMP echo requests with payloads that contain what looks like file fragments. The payloads are larger than normal and the pattern repeats. Which exfiltration technique is being used, and what control would best detect it?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.