
GIAC Offensive AI Analyst
Domain 1Objective 2
Social Engineering Fundamentals GOAA Practice Questions (Page 1)
Part of the AI Foundations and Social Engineering domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
5concepts
Questions 1–5
- 1
An organization is reviewing its incident response after a smishing attack that compromised several mobile devices. The attack used SMS messages that appeared to be from the company's IT help desk, asking users to click a link to 'update their mobile device certificate'. The link led to a malicious app installation. Which of the following countermeasures would have been most effective in preventing the installation of the malicious app?
Select an answer first - 2
A social engineering consultant is planning an in-person engagement. The consultant has gathered detailed information about the target's organizational structure, internal jargon, and the name of the facility manager. The consultant plans to dress as a maintenance worker and claim to need access to a server room to 'check the HVAC'. Which stage of the attack cycle does this preparation represent, and which psychological trigger is being used?
Select an answer first - 3
A security team is designing a phishing simulation for a company where employees are highly educated but overconfident in their ability to detect phishing. The team wants to measure susceptibility while also improving detection skills. Which approach best addresses the overconfidence bias and provides actionable data?
Select an answer first - 4
An organization has implemented strong email filtering and user training for phishing. However, a recent incident involved an attacker calling the finance department, pretending to be the CEO, and instructing an urgent wire transfer to a 'new vendor'. The call appeared to come from a number that matched the CEO's office. Which attack vector was used, and what additional control would have been most effective in preventing this specific incident?
Select an answer first - 5
An organization is considering implementing a security awareness program that includes simulated phishing, vishing, and smishing campaigns. The budget is limited, and the CISO wants to prioritize the vector that poses the highest risk based on the organization's threat model. The organization has recently experienced a successful smishing attack that led to a data breach. Which factor should most influence the decision?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.