
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 1Objective 2
Windows Execution and Memory Foundations GXPN Practice Questions (Page 1)
Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 1–5
- 1
What is the first step in the Windows process creation sequence?
Select an answer first - 2
A penetration tester is performing a vulnerability assessment on a Windows system. They want to execute code that directly accesses hardware and modifies page tables. Which execution mode is required?
Select an answer first - 3
A security team is hardening a Windows application against exploitation. They have enabled DEP, ASLR, and CFG. An attacker discovers a vulnerability that allows writing to an arbitrary memory address. Which mitigation would most likely prevent the attacker from executing code on the heap?
Select an answer first - 4
A penetration tester is exploiting a heap overflow in a Windows application. They want to place a fake chunk header to bypass the heap manager's validation. Which field in the chunk header is used to verify the chunk's size and prevent overlapping chunks?
Select an answer first - 5
A security researcher is analyzing a heap-based buffer overflow in a Windows application. They notice that the heap manager uses a lookaside list for small allocations. What is the primary purpose of the lookaside list?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.