
GIAC Offensive AI Analyst
Domain 2Objective 4
Bypassing Defensive Controls GOAA Practice Questions (Page 8)
Part of the AI-Driven Offensive Operations domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~20–32 in this domain), expect 5–8 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
5concepts
Questions 36–40
- 36
A red team is testing an email gateway that uses a proprietary NLP model to filter phishing. The team has no access to the model's parameters or gradients, but they can submit emails and observe whether each is blocked. They have a local surrogate model trained on similar data. Which technique would allow them to craft emails that evade the gateway?
Select an answer first - 37
A security team deploys an AI-based malware detector that uses a deep neural network to classify executable files. During a red-team exercise, an analyst wants to craft a malicious executable that evades this detector without having access to the model's internal parameters. The analyst only has the ability to submit files and observe whether they are flagged. Which approach is most appropriate?
Select an answer first - 38
A company uses an AI-based email security gateway that employs both a spam filter and a phishing detector. The phishing detector is a deep learning model that analyzes email text and URLs. A penetration tester has successfully evaded the phishing detector by using homoglyphs in URLs. The security team wants to mitigate this vulnerability without blocking legitimate emails that use internationalized domain names. Which mitigation is most appropriate?
Select an answer first - 39
A security analyst is testing an AI-based malware classifier that is deployed as a black box. The analyst wants to generate adversarial examples that are misclassified by the classifier. The analyst has a large dataset of benign and malicious files. Which approach is most likely to succeed?
Select an answer first - 40
An organization uses an AI-based web application firewall (WAF) that detects SQL injection attacks using a machine learning model. A red team finds that adding certain characters to the payload evades detection. The organization wants to implement a defense that is robust against such evasion. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GOAA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.