
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 1
Practical Cryptography GXPN Practice Questions (Page 7)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 48 practice questions to prepare you well beyond it. (estimate)
48questions here
10free pages
8concepts
Questions 31–35
- 31
A developer is implementing a file-integrity monitoring script that hashes files and stores the hashes in a database. An attacker with write access to the database could replace both the files and the hashes. Which additional control should the developer implement to detect this?
Select an answer first - 32
A security analyst is writing a PowerShell script to encrypt sensitive configuration data at rest. The script must ensure that the same plaintext does not produce the same ciphertext each time. Which approach should the script use?
Select an answer first - 33
Which of the following is a known vulnerability of the basic Diffie-Hellman key exchange if no authentication is used?
Select an answer first - 34
A penetration tester is assessing a system that uses AES-128-CBC with PKCS#7 padding. The tester sends a modified ciphertext to the server and observes that the server returns a different error for valid padding versus invalid padding. Which attack can the tester perform?
Select an answer first - 35
A Python script needs to generate a random key for AES encryption. Which method should the script use to ensure the key is cryptographically secure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.