
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 2Objective 1
Bypassing Linux Exploit Mitigations GXPN Practice Questions (Page 1)
Part of the Exploit Mitigation Bypass Techniques domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 3–6 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)
22questions here
5free pages
9concepts
Questions 1–5
- 1
When NX is enabled, an attacker cannot directly execute shellcode placed on the stack. Which technique allows code execution by reusing existing instructions already present in executable memory?
Select an answer first - 2
A tester is exploiting a 64-bit binary with PIE and ASLR enabled. The tester has a buffer overflow that allows overwriting the saved return address. The tester has a single information leak that reveals the address of a function inside the binary. What is the most reliable way to bypass ASLR and PIE?
Select an answer first - 3
Which of the following is a common prerequisite for reliably bypassing ASLR in a 64-bit Linux binary?
Select an answer first - 4
What is the purpose of a seccomp sandbox in a Linux process?
Select an answer first - 5
Which technique is specifically used to bypass Full RELRO by resolving a function symbol dynamically without relying on a writable GOT?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.