
GIAC Defending Advanced Threats
Domain 1Objective 2
Payload Execution GDAT Practice Questions (Page 7)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 31–35
- 31
An organization is concerned about attackers using command-line tools like cmd.exe and PowerShell to execute payloads. They want to implement a control that reduces the risk without breaking legitimate administrative scripts. Which control would be most appropriate?
Select an answer first - 32
A security analyst is investigating a compromised host where the attacker used a reflective DLL injection technique to load a payload into a legitimate process. The payload was never written to disk. Which forensic artifact would be most useful for confirming this activity?
Select an answer first - 33
A malware sample uses a sleep timer that is longer than the typical sandbox analysis window and only executes its payload after the timer expires. Which evasion technique is this?
Select an answer first - 34
A security analyst notices that a legitimate Windows binary (e.g., certutil.exe) is being used to decode a base64-encoded file and then execute it. Which technique is the attacker using?
Select an answer first - 35
What is the primary goal of obfuscation as an evasion strategy during payload execution?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.