
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 2Objective 2
Bypassing Windows Memory Protections GXPN Practice Questions (Page 5)
Part of the Exploit Mitigation Bypass Techniques domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 3–6 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
Questions 21–23
- 21
Which Windows mitigation validates that the exception handler chain is intact before dispatching an exception, making it harder to exploit SEH overwrites?
Select an answer first - 22
Which Windows API function can be used to allocate memory with the PAGE_EXECUTE_READWRITE protection, potentially enabling an attacker to bypass DEP by making a memory region executable?
Select an answer first - 23
You are exploiting a heap overflow in a Windows application that uses the Low Fragmentation Heap (LFH) and has heap integrity checks enabled. You need to achieve arbitrary write. What is the most effective technique?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GXPN
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.