
GIAC Information Security Fundamentals
Domain 3Objective 2
Intrusion and Initial Access Techniques GISF Practice Questions (Page 1)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
9concepts
Questions 1–5
- 1
Which of the following is an example of a social engineering tactic used to gain initial access?
Select an answer first - 2
A web server running an outdated content management system is compromised when an attacker sends a crafted request that exploits a known SQL injection flaw. The attacker then installs a backdoor to maintain access. Which intrusion lifecycle phase is the SQL injection exploit?
Select an answer first - 3
Which of the following is a common type of software vulnerability that attackers exploit to gain initial access?
Select an answer first - 4
A security analyst reviews logs and sees that an attacker gained access to a server by using a valid account after guessing the password through a brute-force attack. Which initial access vector is this?
Select an answer first - 5
Which phase of the intrusion lifecycle involves the attacker moving from one compromised system to another within the network to reach a high-value target?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.