
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 5Objective 1
Endpoint Control Evasions and Escalation GXPN Practice Questions (Page 5)
Part of the Endpoint Evasion, Privilege Escalation, and Product Security Testing domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 73 practice questions to prepare you well beyond it. (estimate)
73questions here
15free pages
20concepts
Questions 21–25
- 21
A security researcher is analyzing a vendor's security patch to understand the underlying vulnerability. The patch modifies a single function in a binary. Which reverse engineering technique is most effective for identifying the vulnerability?
Select an answer first - 22
A penetration tester is targeting a Windows workstation that has a strict application whitelisting policy allowing only signed Microsoft executables to run. The tester has a DLL payload that needs to be executed in the context of a legitimate application. Which technique would most likely bypass the whitelisting control?
Select an answer first - 23
What is a common way to exploit a misconfigured service for privilege escalation?
Select an answer first - 24
A red team has achieved code execution on a Windows 10 endpoint protected by a next-gen AV that uses both signature and behavioral detection, and an EDR that hooks user-mode APIs and monitors ETW. The team needs to run a custom credential-dumping tool that is known to trigger behavioral detections. The team also wants to avoid alerting the SOC. Which combination of techniques would be most effective?
Select an answer first - 25
What is the purpose of patch analysis in product security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.