Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Offensive AI Analyst

Domain 2Objective 2

Network Scanning and Vulnerability Detection GOAA Practice Questions (Page 4)

Part of the AI-Driven Offensive Operations domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~20–32 in this domain), expect 5–8 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
6concepts

Questions 16–20

  1. 16expert · hard

    A penetration tester is scanning a target and finds an open port 443. The tester runs nmap -sV and gets the following output: '443/tcp open ssl/http Apache httpd 2.4.49'. The tester knows that Apache 2.4.49 has a critical RCE vulnerability. However, the tester also notices that the server may be behind a load balancer. What is the most important next step?

    Select an answer first
  2. 17application · medium

    A security operations center (SOC) wants to automate the triage of vulnerability scan results from multiple scanners. The SOC receives thousands of findings daily and needs to reduce the time analysts spend on false positives. Which AI technique would be most effective for this task?

    Select an answer first
  3. 18application · medium

    A penetration tester is scanning an internal network with a vulnerability scanner. The scanner reports a critical vulnerability in Apache Struts on a web server, but the tester knows the server is actually running a patched version. Which action should the tester take first?

    Select an answer first
  4. 19expert · hard

    A security team is using a vulnerability scanner that relies on a database of known vulnerabilities. The scanner is producing a high number of false positives because it is flagging services that have already been patched. The team wants to reduce false positives without missing real vulnerabilities. Which approach should the team take?

    Select an answer first
  5. 20expert · hard

    A security team is using a vulnerability scanner that relies on a plugin database. The scanner reports a critical vulnerability in a custom web application, but the team cannot find any CVE for it. The scanner's plugin may be using heuristic detection. What is the best course of action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.