Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Offensive AI Analyst

Domain 2Objective 3

Using AI for Web Exploitation GOAA Practice Questions (Page 2)

Part of the AI-Driven Offensive Operations domain, which makes up ~40% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~20–32 in this domain), expect 5–8 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)

30questions here
6free pages
5concepts

Questions 6–10

  1. 6expert · hard

    A red team is using an AI-driven orchestration tool to automate the exploitation of a web application. The tool has identified a stored XSS vulnerability in a comment field and a CSRF vulnerability in the password change form. The team wants to chain these vulnerabilities to take over an administrator account. The administrator is known to visit the comment page regularly. Which exploitation chain is most effective?

    Select an answer first
  2. 7expert · medium

    A red team is building an automated exploitation workflow for a web application that has both a staging and a production environment. The workflow must run against staging first, and only proceed to production if the staging run is successful and the client approves. The workflow must also handle the case where the AI tool generates a payload that works in staging but fails in production due to environment differences. What is the best design?

    Select an answer first
  3. 8application · medium

    A red team is automating the exploitation of a web application using an AI-driven orchestration tool. The tool is configured to chain multiple vulnerabilities: first, an SQL injection to extract user credentials, then a session fixation attack to impersonate a user. The team wants to ensure that the entire chain is executed reliably. Which configuration is most important?

    Select an answer first
  4. 9foundation · medium

    What is a common input source that AI-based vulnerability discovery tools use to identify potential web application flaws?

    Select an answer first
  5. 10expert · medium

    A penetration testing firm is using an AI-assisted vulnerability scanner to assess a client's web application. The scanner uses a machine learning model to identify potential vulnerabilities. The client requires that the scanner not send any exploit payloads to the production environment, only benign requests. The scanner has identified a potential SQL injection point. What is the best way to validate the finding without violating the constraint?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GOAA” is a trademark of its owner, used for identification only.