Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Exploit Researcher and Advanced Penetration Tester

Domain 3Objective 3

Traffic Interception and Manipulation GXPN Practice Questions (Page 3)

Part of the Network and Infrastructure Attacks domain, which makes up ~14% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 3–6 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 11–15

  1. 11foundation · easy

    Which protocol vulnerability is exploited when an attacker performs a man-in-the-middle attack by intercepting DNS queries and returning malicious IP addresses?

    Select an answer first
  2. 12application · medium

    A penetration tester is performing a MITM attack on a network that uses unencrypted HTTP for a legacy application. The tester wants to modify the data in transit to change a transaction amount. Which tool would allow the tester to intercept and modify HTTP requests and responses in real time?

    Select an answer first
  3. 13application · medium

    A security analyst is reviewing network logs and sees that a client is receiving DNS responses from an unexpected IP address. The analyst suspects DNS spoofing. Which protocol feature would prevent this type of attack?

    Select an answer first
  4. 14application · medium

    A security engineer is reviewing network traffic and notices that a client is sending HTTP requests to a server that should be using HTTPS. The engineer suspects an SSL stripping attack. Which protocol feature would prevent this attack?

    Select an answer first
  5. 15application · medium

    A penetration tester is performing a MITM attack on a network that uses HTTP for internal web applications. The tester successfully intercepts traffic and wants to modify the data being sent from the client to the server. Which protocol vulnerability is the tester exploiting, and what is the most direct manipulation technique?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.