Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 2Objective 1

Bypassing Linux Exploit Mitigations GXPN Practice Questions (Page 2)

Part of the Exploit Mitigation Bypass Techniques domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 3–6 from this objective — we provide 22 practice questions to prepare you well beyond it. (estimate)

22questions here
5free pages
9concepts

Questions 6–10

  1. 6foundation · easy

    Which of the following is a common technique to bypass CFI?

    Select an answer first
  2. 7foundation · easy

    An attacker has a stack buffer overflow in a program compiled with all standard mitigations: ASLR, NX, stack canaries, and Full RELRO. They have a format string vulnerability that can leak arbitrary memory. Which of the following is the most efficient first step to exploit this vulnerability?

    Select an answer first
  3. 8foundation · easy

    When a binary is compiled as PIE, what is the primary challenge for an attacker?

    Select an answer first
  4. 9application · medium

    A tester is exploiting a stack overflow in a binary with a stack canary and ASLR enabled. The tester has a way to leak the canary value. Which additional information is needed to build a reliable ROP chain?

    Select an answer first
  5. 10foundation · easy

    An attacker has a buffer overflow vulnerability but ASLR is enabled. They do not have a way to leak a memory address. Which technique could still allow them to redirect execution to a function within the same binary?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.