
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 1Objective 2
Windows Execution and Memory Foundations GXPN Practice Questions (Page 8)
Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
8concepts
Questions 36–40
- 36
A security researcher is analyzing a kernel exploit and needs to understand how a virtual address is translated to a physical address. Which structure is used to store the physical page frame number for a given virtual page?
Select an answer first - 37
You are reverse engineering a 64-bit Windows binary and have found a stack overflow in a function that uses stack cookies. The function has a local buffer and a stack cookie placed between the buffer and the saved return address. You have an arbitrary read primitive that allows you to read the stack cookie. What is the most effective way to exploit the overflow?
Select an answer first - 38
A security team is hardening a Windows application against return-oriented programming (ROP) attacks. They have enabled DEP and ASLR. Which additional mitigation would specifically prevent an attacker from redirecting execution to an unintended indirect call target?
Select an answer first - 39
What is the purpose of free lists in the Windows heap?
Select an answer first - 40
What is the primary purpose of Data Execution Prevention (DEP)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.