
GIAC Offensive AI Analyst
Domain 3Objective 2
Creating Malicious Software with AI GOAA Practice Questions (Page 7)
Part of the AI-Enhanced Malware and Deepfakes domain, which makes up ~32% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~16–26 in this domain), expect 5–9 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
5concepts
Questions 31–32
- 31
A malware analyst is testing whether a deep learning-based PE file classifier can be evaded. The analyst has access to the model's confidence scores but not its internal weights. Which technique is most appropriate to craft an evasive PE file?
Select an answer first - 32
A security researcher is developing a proof-of-concept to demonstrate how an AI model could generate a polymorphic version of a known benign utility. The goal is to produce variants that evade signature-based antivirus while preserving the utility's original functionality. Which approach best achieves this objective?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GOAA
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.