
GIAC Foundational Cybersecurity Technologies
Domain 6Objective 1
Exploitation & Mitigation GFACT Practice Questions (Page 6)
Part of the Offensive Security and Defense domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 26–30
- 26
A security architect is designing a mitigation strategy for a critical application that cannot be taken offline for patching. The application has a known remote code execution vulnerability. The architect must balance the need to protect the application with the requirement to maintain availability. Which approach best meets these conflicting requirements?
Select an answer first - 27
A system administrator discovers that a service running on a server has a known vulnerability that allows a local user to gain root privileges. The administrator needs to mitigate this risk quickly. Which action is most appropriate?
Select an answer first - 28
What is the primary goal of privilege escalation?
Select an answer first - 29
Which mitigation strategy is most effective in limiting the damage an attacker can do if they compromise a low-privileged user account?
Select an answer first - 30
A company is implementing a security monitoring solution. They want to detect exploitation attempts and also have the ability to block malicious traffic in real time. However, they are concerned about the operational impact of false positives. Which solution best balances detection and prevention while minimizing disruption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.