Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 1Objective 3

Return Oriented Stack-Based Exploits GXPN Practice Questions (Page 6)

Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts

Questions 26–29

  1. 26application · easy

    A tester is using ROPgadget to find a gadget that pops two values from the stack and then returns. Which gadget should the tester search for?

    Select an answer first
  2. 27foundation · easy

    In a ROP chain, what is the role of the data placed immediately after each gadget address on the stack?

    Select an answer first
  3. 28foundation · easy

    Which of the following instruction sequences would be considered a useful ROP gadget for setting a register to a controlled value?

    Select an answer first
  4. 29expert · hard

    A tester is exploiting a 64-bit binary with NX and ASLR enabled. The binary has a stack overflow and a format string vulnerability that leaks a stack address. The tester wants to call system('/bin/sh') but does not know the libc base. The binary does not import system. Which technique is most likely to succeed?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to GXPN

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.