
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 5Objective 1
Endpoint Control Evasions and Escalation GXPN Practice Questions (Page 15)
Part of the Endpoint Evasion, Privilege Escalation, and Product Security Testing domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 73 practice questions to prepare you well beyond it. (estimate)
73questions here
15free pages
20concepts
Questions 71–73
- 71
What is the main advantage of fuzzing over manual code review?
Select an answer first - 72
During a Windows privilege escalation assessment, you find that a third-party service runs as SYSTEM and its executable file is writable by the Everyone group. You need to escalate privileges to SYSTEM. Which technique is most appropriate?
Select an answer first - 73
What is the general approach to exploiting a kernel vulnerability?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GXPN
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.