Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 5Objective 3

Source Code Based Fuzzing Techniques GXPN Practice Questions (Page 6)

Part of the Endpoint Evasion, Privilege Escalation, and Product Security Testing domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)

51questions here
11free pages
10concepts

Questions 26–30

  1. 26expert · hard

    A security researcher is fuzzing a complex file format parser. The researcher has a large seed corpus, but the fuzzer is spending most of its time mutating inputs that do not increase coverage. The researcher wants to improve the fuzzer's efficiency. Which action will have the most impact?

    Select an answer first
  2. 27application · medium

    A penetration tester is fuzzing a file parser that accepts a proprietary binary format. The tester has a small set of valid sample files from the vendor. The goal is to find memory-corruption bugs quickly. The tester plans to use a mutation-based fuzzer. Which initial step will most improve the effectiveness of the fuzzing campaign?

    Select an answer first
  3. 28application · medium

    A security engineer is fuzzing a C library that parses configuration files. The library has a complex state machine with many conditional branches based on the order of tokens. The engineer wants to maximize the discovery of deep logic bugs while minimizing the number of test cases that hit the same code paths. Which approach should the engineer use?

    Select an answer first
  4. 29foundation · easy

    Which of the following is a coverage-guided fuzzing engine?

    Select an answer first
  5. 30expert · hard

    A security researcher is fuzzing a library that processes image files. The library has a known bug that only triggers when a specific combination of image dimensions and color depth is present. The researcher is using a coverage-guided fuzzer with a seed corpus of valid images. The fuzzer is not finding the bug. Which action is most likely to help?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.