
GIAC Defending Advanced Threats
Domain 1Objective 2
Payload Execution GDAT Practice Questions (Page 5)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 21–25
- 21
An EDR alert shows that a process (e.g., notepad.exe) has a memory region that is both writable and executable, and the region contains a shellcode pattern. The process was not known to be malicious. Which response is most appropriate?
Select an answer first - 22
A security team is investigating a malware infection where the payload was delivered via a spear-phishing email and executed using a script. The script was obfuscated to avoid detection. Which mitigation would have been most effective at preventing the execution?
Select an answer first - 23
A security team is evaluating EDR solutions. They need to detect payload execution that uses obfuscated PowerShell scripts and process injection. Which EDR capability is most important?
Select an answer first - 24
A forensic analyst is investigating a host where malware executed without creating any files on disk. The malware used a technique that allocates memory, writes code, and then executes it. Which detection method would have been most likely to catch this?
Select an answer first - 25
A red team is testing a client's EDR solution. They plan to use a process injection technique that is known to be detected by the EDR. They also want to avoid writing any payload to disk. Which approach would be most likely to evade the EDR while still achieving code execution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.