Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 1Objective 3

Return Oriented Stack-Based Exploits GXPN Practice Questions (Page 1)

Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts

Questions 1–5

  1. 1foundation · easy

    When developing a ROP exploit, what is the purpose of using a debugger like GDB?

    Select an answer first
  2. 2application · medium

    A tester is exploiting a 32-bit binary with NX enabled but ASLR disabled. The binary has a stack overflow and the tester knows the address of system() and '/bin/sh' in libc. Which technique should the tester use?

    Select an answer first
  3. 3foundation · easy

    In the x86-64 System V calling convention, which register holds the first integer/pointer argument to a function?

    Select an answer first
  4. 4application · hard

    You are exploiting a 64-bit Linux binary with NX enabled and ASLR active. You have a stack buffer overflow and want to call mprotect() to make the stack executable, then jump to shellcode placed on the stack. Which approach is most viable?

    Select an answer first
  5. 5application · easy

    A tester is using ROPgadget to find gadgets in a binary. The tester needs to move a value from rax to rdi. Which gadget should the tester look for?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.