
GIAC Security Operations Certified
Domain 2Objective 3
HTTP(S) Analysis and Attacks GSOC Practice Questions (Page 8)
Part of the Network and Event Analysis domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~19–30 in this domain), expect 5–8 from this objective — we provide 77 practice questions to prepare you well beyond it. (estimate)
77questions here
16free pages
23concepts
Questions 36–40
- 36
Which log entry is most indicative of a brute-force login attack?
Select an answer first - 37
Which characters are the primary target for HTTP header injection?
Select an answer first - 38
Which part of an HTTP response indicates whether the request was successful?
Select an answer first - 39
A security analyst is investigating a series of failed login attempts against a web application that uses a reverse proxy in front of an origin server. The proxy forwards requests with the header 'Content-Length' stripped and instead relies on 'Transfer-Encoding: chunked'. The origin server, however, honors both headers. During analysis, the analyst notices a request where the proxy saw a single request but the origin server processed it as two separate requests. The second request contained a 'Cookie: session=admin' header. Which HTTP attack technique is most consistent with this observation?
Select an answer first - 40
What is the result of a successful CRLF injection into an HTTP header?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GSOC” is a trademark of its owner, used for identification only.