
GIAC Defending Advanced Threats
Domain 1Objective 2
Payload Execution GDAT Practice Questions (Page 9)
Part of the Initial Access and Execution domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
6concepts
Questions 41–44
- 41
A security team is configuring an EDR solution to detect malicious PowerShell usage. They want to detect obfuscated scripts that use base64 encoding. Which EDR capability is most effective?
Select an answer first - 42
A threat actor is using a fileless malware technique that executes a PowerShell script directly in memory, avoiding writing any payload to disk. The organization has endpoint detection and response (EDR) deployed. Which detection approach would be most effective for identifying this activity?
Select an answer first - 43
An incident responder observes that a legitimate process (e.g., explorer.exe) has a thread that was created by a different process. The thread's start address points to a memory region that is not backed by a known module. Which technique is most likely being used?
Select an answer first - 44
A security team is analyzing a malware sample that uses encryption to hide its payload and only decrypts it in memory during execution. The malware also checks for the presence of virtual machines and debugging tools before running. Which detection technique would be most effective at identifying this malware?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GDAT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.