Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 1Objective 2

Payload Execution GDAT Practice Questions (Page 4)

Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts

Questions 16–20

  1. 16foundation · easy

    Which of the following is an example of an anti-sandboxing technique used during payload execution?

    Select an answer first
  2. 17expert · hard

    A red team operator needs to execute a payload on a target that has an EDR with strong behavioral detection. The payload must run without writing to disk and must avoid triggering EDR alerts. Which approach is most likely to succeed?

    Select an answer first
  3. 18application · medium

    A red team operator needs to execute a payload on a target Windows host without writing any files to disk. The payload must run in the context of the current user and avoid triggering file-based detection. Which approach best meets these requirements?

    Select an answer first
  4. 19foundation · easy

    Which statement best describes payload execution in the context of initial access?

    Select an answer first
  5. 20foundation · easy

    What is the primary purpose of process injection in the context of payload execution?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.