Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 3

HTTP(S) Analysis and Attacks GSOC Practice Questions (Page 13)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 77 practice questions to prepare you well beyond it. (estimate)

77questions here
16free pages
23concepts

Questions 61–65

  1. 61foundation · easy

    Why can HTTP Parameter Pollution be dangerous?

    Select an answer first
  2. 62application · medium

    A user reports that their account was used to transfer funds without their knowledge. The SOC analyst reviews the proxy logs and finds a request to '/transfer.php' with a POST body containing 'amount=1000&toAccount=12345'. The request includes a 'Referer' header pointing to 'https://evil.example.com/phish'. The user's session cookie was not present in the request. Which attack best explains this incident?

    Select an answer first
  3. 63application · medium

    A SOC analyst is analyzing web server logs and finds the following entries: 'GET /products.php?id=1' followed by 'GET /products.php?id=2', 'GET /products.php?id=3', and so on, up to 'GET /products.php?id=1000'. The requests come from a single IP address and occur within a 5-second window. The responses are all 200 OK. Which conclusion is most consistent with this observation?

    Select an answer first
  4. 64application · medium

    An analyst is reviewing HTTP logs and finds a request to '/download.php?file=..%2F..%2Fetc%2Fpasswd'. The server responds with a 200 OK and the response body contains 'root:x:0:0:root:/root:/bin/bash'. What is the most likely vulnerability, and what is the best immediate mitigation?

    Select an answer first
  5. 65application · medium

    A SOC analyst is reviewing HTTP logs and finds a request to '/profile' with the following headers: 'Cookie: session=abc123' and 'Referer: https://evil.example.com/steal'. The response is a 200 OK with the user's profile page. The analyst notices that the application does not set the 'SameSite' attribute on the session cookie. Which attack is most likely to succeed?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.