
GIAC Offensive AI Analyst
Domain 2Objective 2
Network Scanning and Vulnerability Detection GOAA Practice Questions (Page 6)
Part of the AI-Driven Offensive Operations domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~20–32 in this domain), expect 5–8 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
6concepts
Questions 26–30
- 26
A network administrator needs to scan a server to determine which TCP ports are open. The administrator wants to avoid completing full TCP connections to reduce the load on the server. Which scan type should the administrator use?
Select an answer first - 27
A red team is using an AI-enhanced vulnerability scanner that automatically adjusts its scanning behavior based on the target's responses. The scanner is designed to reduce the number of probes sent to the target to avoid detection. However, the scanner is producing a high number of false negatives, missing vulnerabilities that are actually present. The team needs to improve the scanner's recall without significantly increasing the chance of detection. Which adjustment should the team make?
Select an answer first - 28
A penetration tester is scanning a target and finds an open port 443. The tester wants to identify the exact service and version running behind the port. Which nmap command should the tester use?
Select an answer first - 29
A network administrator is conducting a security assessment and needs to identify which hosts on a subnet are running a UDP-based service. The administrator wants to avoid disrupting the service and needs to complete the scan quickly. Which scanning technique is most appropriate?
Select an answer first - 30
A security analyst has completed a vulnerability scan and received a report with the following findings: a critical remote code execution vulnerability in a web server, a high-severity SQL injection in a database application, a medium-severity cross-site scripting (XSS) in a web application, and a low-severity information disclosure in a network service. The analyst needs to prioritize remediation efforts. Which vulnerability should be addressed first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.