
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 1
Practical Cryptography GXPN Practice Questions (Page 4)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 16–20
- 16
A developer is implementing a file integrity monitoring system. The system needs to detect any modification to files, including accidental changes and malicious tampering. Which approach is most appropriate?
Select an answer first - 17
A penetration tester is writing a Python script to demonstrate how a client can verify a server's identity during TLS handshake. The script needs to validate the server's certificate chain and confirm the server possesses the corresponding private key. Which steps should the script perform?
Select an answer first - 18
In asymmetric cryptography, what is the relationship between the public key and the private key?
Select an answer first - 19
A company wants to implement a secure email system where emails are encrypted so only the intended recipient can read them. Which key should be used to encrypt the email?
Select an answer first - 20
Which of the following is a common use of the 'hashlib' module in Python?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.