
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 1
Practical Cryptography GXPN Practice Questions (Page 3)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 11–15
- 11
A penetration tester is writing a script to verify a digital signature on a firmware update. The script has access to the signer's public key but not the private key. Which operation should the script perform?
Select an answer first - 12
A penetration tester is assessing a legacy application that uses a fixed pre-shared key for all client-server encryption. The tester wants to demonstrate a more secure key exchange that also provides forward secrecy. Which approach should the tester recommend?
Select an answer first - 13
A security team is investigating a breach where an attacker was able to forge authentication tokens. The tokens are created by concatenating a user ID and a timestamp, then hashing with SHA-256. The hash is not keyed. Which weakness allowed the forgery?
Select an answer first - 14
A developer is writing a script to verify the integrity of downloaded firmware. The script currently uses MD5. A security review flags this as insufficient. Which change should the developer make?
Select an answer first - 15
Which statement best describes symmetric encryption?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.