
GIAC Security Operations Certified
Domain 2Objective 3
HTTP(S) Analysis and Attacks GSOC Practice Questions (Page 5)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 77 practice questions to prepare you well beyond it. (estimate)
77questions here
16free pages
23concepts
Questions 21–25
- 21
What is the primary risk of allowing unrestricted file uploads on a web application?
Select an answer first - 22
Which component of an HTTP response contains the actual content requested by the client, such as HTML or JSON?
Select an answer first - 23
Which HTTP request is typical of a malicious file upload attempt?
Select an answer first - 24
A SOC analyst is reviewing HTTP traffic to a compromised web server. The analyst notices a series of POST requests to /images/upload.php with a body containing base64-encoded data. The responses are all 200 OK with a small body. The requests occur at regular intervals of exactly 5 minutes, and the User-Agent string is a custom string 'Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)'. Which combination of HTTP characteristics is most indicative of a web shell or backdoor?
Select an answer first - 25
Which component of an HTTP request specifies the action the client wants the server to perform?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.