
GIAC Defending Advanced Threats
Domain 1Objective 1
Payload Delivery GDAT Practice Questions (Page 2)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 6–10
- 6
What is the purpose of payload obfuscation?
Select an answer first - 7
A company's users report that after visiting a popular news website, their browsers become unresponsive and then a suspicious executable is launched. The security team suspects malvertising and an exploit kit. The website itself is legitimate and has not been defaced. Which combination of controls would be most effective in preventing this type of payload delivery?
Select an answer first - 8
A security team is investigating a breach at a research lab. They find that a USB drive left in the parking lot was plugged into a scientist's workstation. The USB drive contained a file that, when opened, executed a macro that installed a backdoor. Which two concepts are demonstrated?
Select an answer first - 9
What is the defining characteristic of a watering hole attack?
Select an answer first - 10
A security analyst is investigating a breach where employees received emails with a malicious link. The link redirected to a legitimate website that had been compromised with a malicious script. The script exploited a browser vulnerability and delivered a payload that was encoded with base64. Which two techniques are being used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.