
GIAC Offensive AI Analyst
Domain 2Objective 4
Bypassing Defensive Controls GOAA Practice Questions (Page 6)
Part of the AI-Driven Offensive Operations domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~20–32 in this domain), expect 5–8 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 26–30
- 26
A security researcher is testing an AI-based malware detector that uses a deep neural network. The researcher has white-box access to the model and wants to generate adversarial examples that are robust to the detector's defensive preprocessing, such as input clipping. Which attack technique is most appropriate?
Select an answer first - 27
A company uses an AI-powered email filter that blocks phishing emails by analyzing text and URLs. A penetration tester wants to bypass this filter to deliver a phishing email to employees. The tester has no access to the model's internals but can send test emails and observe whether they are blocked. Which technique is most effective for this black-box scenario?
Select an answer first - 28
A red team is conducting an exercise against an AI-based endpoint detection and response (EDR) system. The team has white-box access to the model but is constrained by a limited time window. They need to generate adversarial examples that are effective against the EDR. Which approach best balances effectiveness and time efficiency?
Select an answer first - 29
A red team is testing a physical access control system that uses a deep learning model to recognize faces. The system is deployed at a high-security facility with both a visible-light camera and an infrared camera. The team has access to a photo of an authorized employee. They want to test whether the system can be bypassed using an adversarial perturbation that works across both camera modalities. The team has white-box access to the visible-light model but only black-box access to the infrared model. Which approach is most likely to succeed?
Select an answer first - 30
A security researcher is testing an AI-based image classifier that is used to detect inappropriate content on a social media platform. The researcher wants to create images that bypass the classifier while still appearing normal to human viewers. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.