
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 5Objective 3
Source Code Based Fuzzing Techniques GXPN Practice Questions (Page 7)
Part of the Endpoint Evasion, Privilege Escalation, and Product Security Testing domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 51 practice questions to prepare you well beyond it. (estimate)
51questions here
11free pages
10concepts
Questions 31–35
- 31
A fuzzing campaign on a network service produced hundreds of crashes. A security analyst wants to prioritize which crashes to investigate first. Which criterion is most useful for triage?
Select an answer first - 32
A tester is fuzzing a text-based configuration parser. They have a seed file that is a valid configuration. They want to use mutation-based fuzzing to find bugs. Which mutation is most likely to trigger a parsing error?
Select an answer first - 33
A fuzzing campaign has produced a crash that causes a segmentation fault in a library function. The crash is reproducible with a specific input file. The analyst needs to determine if the crash is exploitable. Which step should the analyst take first?
Select an answer first - 34
A security team is fuzzing a closed-source binary that is not compiled with any instrumentation. The team wants to use coverage-guided fuzzing to find bugs. Which approach should they take?
Select an answer first - 35
What is the primary input to a generation-based fuzzer?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.