Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Security Operations Certified

Domain 2Objective 3

HTTP(S) Analysis and Attacks GSOC Practice Questions (Page 3)

Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 77 practice questions to prepare you well beyond it. (estimate)

77questions here
16free pages
23concepts

Questions 11–15

  1. 11application · medium

    A SOC analyst is investigating a series of alerts from a web application. The logs show a GET request to /search?q=%3Cscript%3Ealert(document.cookie)%3C/script%3E. The response from the server includes the Content-Type: text/html header, and the application reflects the 'q' parameter value directly into the page without encoding. Which combination of HTTP components in the request and response confirms the most likely attack type?

    Select an answer first
  2. 12expert · hard

    A SOC analyst is reviewing a packet capture from a server that is supposed to only serve web pages. The analyst notices a series of HTTP POST requests to /update with a Content-Type of application/x-www-form-urlencoded. The request bodies are unusually large (several megabytes) and contain data that, when decoded, appears to be a series of SSH protocol messages. The responses are all 200 OK. Which HTTP characteristic is the strongest indicator of tunneling or a covert channel?

    Select an answer first
  3. 13application · medium

    A SOC analyst is reviewing a web application firewall (WAF) log and finds a request to /redirect?url=https://example.com%0d%0aX-Injected:%20true. The WAF blocked the request. The analyst notices that the application uses the 'url' parameter to construct a Location header for redirects. Which HTTP attack is the WAF most likely blocking?

    Select an answer first
  4. 14application · medium

    A SOC analyst is inspecting TLS traffic to a corporate web application. The analyst notices that the server's certificate is signed by a certificate authority that is not in the organization's trusted root store, and the certificate's Subject Alternative Name (SAN) does not match the requested domain. The TLS handshake completes successfully, and the application data is exchanged. Which TLS handshake component should the analyst flag as the primary anomaly?

    Select an answer first
  5. 15foundation · easy

    Which HTTP header is commonly used to mitigate CSRF attacks?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.