
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 1
Practical Cryptography GXPN Practice Questions (Page 6)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 26–30
- 26
What is the primary purpose of the Diffie-Hellman key exchange protocol?
Select an answer first - 27
A security analyst is investigating a potential collision attack on a system that uses MD5 to verify software updates. The analyst wants to demonstrate the practical impact of MD5's weakness. Which attack should the analyst perform?
Select an answer first - 28
Which of the following is a mitigation for side-channel attacks?
Select an answer first - 29
A legal team requires proof that a specific employee approved a financial document. The document is stored in a system that uses digital signatures. What must be true for the signature to provide non-repudiation?
Select an answer first - 30
A penetration tester is analyzing a custom protocol that uses AES-128 in ECB mode to encrypt each block of a message independently. The tester notices that the same plaintext block always produces the same ciphertext block. Which attack is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.