Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 2Objective 2

Bypassing Windows Memory Protections GXPN Practice Questions (Page 5)

Part of the Exploit Mitigation Bypass Techniques domain, which makes up ~9% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~6–11 in this domain), expect 3–6 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts

Questions 21–23

  1. 21foundation · easy

    Which Windows mitigation validates that the exception handler chain is intact before dispatching an exception, making it harder to exploit SEH overwrites?

    Select an answer first
  2. 22foundation · easy

    Which Windows API function can be used to allocate memory with the PAGE_EXECUTE_READWRITE protection, potentially enabling an attacker to bypass DEP by making a memory region executable?

    Select an answer first
  3. 23application · medium

    You are exploiting a heap overflow in a Windows application that uses the Low Fragmentation Heap (LFH) and has heap integrity checks enabled. You need to achieve arbitrary write. What is the most effective technique?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GXPN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.