Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Information Security Fundamentals

Domain 3Objective 3

Post-Exploitation and Advanced Threat Techniques GISF Practice Questions (Page 2)

Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)

53questions here
11free pages
9concepts

Questions 6–10

  1. 6application · medium

    A security team notices a server that frequently sends large volumes of data to a cloud storage service using the built-in 'curl' utility. The data is compressed and encrypted before transmission. The server has no business need to use cloud storage. Which defensive measure would MOST directly detect this activity?

    Select an answer first
  2. 7application · medium

    A security analyst notices that a compromised host sends a small HTTP request to a remote server every 60 seconds. The response contains an encrypted payload that the host executes. The analyst also sees that the host uses the same HTTP request to send small amounts of data back. Which post-exploitation technique is the attacker using?

    Select an answer first
  3. 8expert · hard

    A security analyst is investigating a suspected APT. The analyst finds that a compromised host makes periodic DNS queries to a domain that resolves to different IP addresses, and the host sends small amounts of data encoded in the DNS queries. The organization has strict egress filtering that only allows DNS and HTTPS outbound. Which C2 channel is the attacker using, and why is it effective in this environment?

    Select an answer first
  4. 9foundation · easy

    Which of the following is a common data exfiltration method?

    Select an answer first
  5. 10expert · hard

    A security analyst is investigating a potential data exfiltration incident. The analyst notices that a compromised host is sending data to a cloud storage service via HTTPS, but the volume is low and the traffic appears to be normal web traffic. The analyst suspects that the attacker is using a covert channel. Which technique would be MOST effective in detecting this type of exfiltration?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.