
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 5Objective 1
Endpoint Control Evasions and Escalation GXPN Practice Questions (Page 2)
Part of the Endpoint Evasion, Privilege Escalation, and Product Security Testing domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 73 practice questions to prepare you well beyond it. (estimate)
73questions here
15free pages
20concepts
Questions 6–10
- 6
A penetration tester is assessing a Windows server that is fully patched but has a known vulnerable kernel driver installed by a third-party application. The tester wants to escalate privileges to SYSTEM. Which approach is most appropriate?
Select an answer first - 7
What is the primary goal of a secure code review?
Select an answer first - 8
A penetration tester has access to a Windows 10 workstation as a standard user. The tester needs to run a malicious executable with administrative privileges without triggering a UAC prompt. Which technique would be most effective?
Select an answer first - 9
You are evading a host-based intrusion detection system (HIDS) that monitors file system changes and process creation. You need to maintain persistence on a Windows host without triggering the HIDS. Which technique is most appropriate?
Select an answer first - 10
A security reviewer is examining a web application's source code. The reviewer notices that user input is concatenated directly into an SQL query string. Which vulnerability is most likely present, and what is the best remediation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.