
GIAC Defending Advanced Threats
Domain 1Objective 1
Payload Delivery GDAT Practice Questions (Page 7)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
6concepts
Questions 31–33
- 31
A government agency has identified that a specific group of its employees is being targeted by a watering hole attack. The attackers have compromised a website that the employees visit daily. The agency has already implemented web filtering, browser patching, and endpoint antivirus. The agency is considering additional controls, but it has a limited budget and must choose one. The agency's primary concern is preventing the initial compromise of the employees' workstations. Which control would be most effective?
Select an answer first - 32
A security analyst is responding to an incident where a user clicked a link in a phishing email. The link downloaded a file that, when executed, added a registry key to run a malicious process at startup. Which two techniques are being used?
Select an answer first - 33
A security analyst is investigating a breach at a law firm. The firm's attorneys frequently visit a specific legal research website. The website was compromised and now delivers a payload that exploits a browser vulnerability. After execution, the payload creates a service that runs automatically at startup. Which two techniques are being used?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GDAT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.