
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 2Objective 2
Bypassing Windows Memory Protections GXPN Practice Questions (Page 2)
Part of the Exploit Mitigation Bypass Techniques domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 3–6 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
Questions 6–10
- 6
Which Windows mitigation randomizes the base addresses of modules, heap, and stack to make memory addresses unpredictable for an attacker?
Select an answer first - 7
To bypass Control Flow Guard (CFG), an attacker must redirect control flow to which type of address?
Select an answer first - 8
You are exploiting a Windows service that is compiled with /GS (stack cookies), SafeSEH, and DEP. You have found a stack buffer overflow in a function that does not use exception handlers. You have a memory disclosure that reveals the stack cookie value. What is the most efficient way to achieve code execution?
Select an answer first - 9
When ASLR is enabled, which technique can be used to bypass it by overwriting only the lower bytes of a pointer, leaving the randomized upper bytes intact?
Select an answer first - 10
You are exploiting a heap overflow in a Windows application that uses the LFH (Low Fragmentation Heap) and has DEP enabled. You need to achieve code execution. Which strategy is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.