
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 1Objective 2
Windows Execution and Memory Foundations GXPN Practice Questions (Page 2)
Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 6–10
- 6
A malware analyst is reverse engineering a Windows executable and wants to find the entry point of the program. Which field in the PE header specifies the address where execution begins?
Select an answer first - 7
You are analyzing a Windows PE file and need to determine which functions it imports from system DLLs. You open the file in a hex editor and locate the import table. Which PE structure contains the names of the imported functions?
Select an answer first - 8
In Windows, what is the primary difference between user mode and kernel mode?
Select an answer first - 9
You are exploiting a heap overflow in a 64-bit Windows application that uses the Low Fragmentation Heap (LFH). You have noticed that the LFH uses a bitmap to track which sub-chunks are in use. You have overwritten the metadata of a chunk that is currently in use. Which exploitation technique is most likely to succeed?
Select an answer first - 10
A developer is analyzing a crash dump from a Windows application. They suspect a stack buffer overflow overwrote the return address. Which register should they examine to find the current top of the stack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.