
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 1
Practical Cryptography GXPN Practice Questions (Page 2)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 6–10
- 6
Which of the following is a common cryptographic attack that involves intercepting and potentially altering communications between two parties?
Select an answer first - 7
A security engineer needs to ensure that a configuration file downloaded by clients is authentic and has not been tampered with. The file is distributed over an insecure channel. Which scripting approach should the engineer use?
Select an answer first - 8
What property of a cryptographic hash function ensures that it is computationally infeasible to find two different inputs that produce the same hash output?
Select an answer first - 9
In Python, which library is commonly used for cryptographic operations such as hashing and encryption?
Select an answer first - 10
A security analyst is investigating a suspected malware infection. The malware modifies a system binary, and the analyst wants to verify the integrity of the binary against a known-good hash. The analyst has the original SHA-256 hash from the vendor. Which action should the analyst take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.