Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 1Objective 1

Payload Delivery GDAT Practice Questions (Page 5)

Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
6concepts

Questions 21–25

  1. 21expert · hard

    A security analyst is investigating a breach where users were infected after visiting a popular website. The website displayed ads that redirected to a malicious page that exploited a browser vulnerability. The payload was encrypted and then executed in memory, with no file written to disk. The payload also created a scheduled task for persistence. Which two techniques are being used?

    Select an answer first
  2. 22foundation · easy

    What is the primary purpose of establishing persistence on a compromised system?

    Select an answer first
  3. 23expert · hard

    A security team is investigating a breach where users were infected after visiting a popular online forum. The forum had been compromised with a malicious script that exploited a browser vulnerability. The script delivered a payload that was encrypted with a custom algorithm. Which two techniques are being used?

    Select an answer first
  4. 24application · medium

    A defense contractor discovers that a niche industry forum frequently visited by its engineers has been compromised. The forum now serves a malicious script that exploits a known browser vulnerability. Which attack technique is being used?

    Select an answer first
  5. 25application · medium

    A security team is responding to an incident where a user clicked a malicious link in a phishing email. The link downloaded a JavaScript file that, when executed, created a new Windows service to run a malicious binary. The team wants to prevent this type of persistence from being established in the future. Which control would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.