
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 4Objective 2
Practical Scripting for Offensive Operations GXPN Practice Questions (Page 8)
Part of the Offensive Scripting and Cryptography domain, which makes up ~18% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–22 in this domain), expect 7–11 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
8concepts
Questions 36–40
- 36
You are automating a web application scan with Burp Suite and need to extract all unique parameters from the scan results. The results are in a Burp project file. Which scripting approach is most efficient?
Select an answer first - 37
You have a Python script that sends a large number of HTTP requests to a web server. The script is slow because it sends requests sequentially. You need to improve performance without overwhelming the server. Which approach is best?
Select an answer first - 38
Which optimization technique is most appropriate for a Python script that repeatedly performs the same expensive computation inside a loop?
Select an answer first - 39
You are writing a Python script to generate a payload that must be encrypted with AES-256-CBC before being sent to a C2 server. The key is derived from a passphrase. Which approach correctly implements this?
Select an answer first - 40
Which Python module provides low-level socket programming to create custom TCP connections?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.