Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 1Objective 2

Payload Execution GDAT Practice Questions (Page 3)

Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 11–15

  1. 11application · medium

    A security analyst notices that a legitimate Windows utility, certutil.exe, is being used to download and decode a base64-encoded file from a remote server, and then the decoded content is executed via a scheduled task. The organization has endpoint detection and response (EDR) deployed. Which detection strategy would most effectively identify this activity?

    Select an answer first
  2. 12expert · hard

    A security analyst is investigating a host that was compromised using a fileless attack. The attacker used a PowerShell script to download and execute a payload directly in memory. The analyst has access to the EDR console, which shows PowerShell process creation events but not the script content. Which additional data source would be most useful for determining what the script did?

    Select an answer first
  3. 13expert · hard

    A malware developer wants to evade an EDR that uses machine learning to detect malicious PowerShell scripts. The developer wants to use a technique that is difficult for the ML model to generalize. Which approach is most likely to evade the ML-based detection?

    Select an answer first
  4. 14expert · hard

    A security analyst is investigating a malware sample that uses a multi-stage payload. The first stage is a small dropper that downloads an encrypted second stage and decrypts it in memory. The malware also uses anti-sandboxing techniques to avoid analysis. Which detection strategy would be most effective at identifying this malware?

    Select an answer first
  5. 15application · medium

    An organization wants to reduce the risk of attackers using living-off-the-land binaries (LOLBins) like PowerShell and WMI for execution. They have a mature EDR deployment and a strict change management process. Which approach would be most effective?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.