
GIAC Exploit Researcher and Advanced Penetration Tester
Domain 1Objective 4
Windows Overflows and Execution Control GXPN Practice Questions (Page 4)
Part of the Exploitation Foundations and Memory Corruption domain, which makes up ~26% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~18–31 in this domain), expect 5–8 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
9concepts
Questions 16–20
- 16
In a typical Windows process memory layout, which region is used for dynamic memory allocation during runtime and grows toward higher memory addresses?
Select an answer first - 17
What is the primary purpose of an egg hunter in Windows exploitation?
Select an answer first - 18
A penetration tester is exploiting a heap overflow in a Windows application that uses the LFH (Low Fragmentation Heap). The application has DEP and ASLR enabled. The tester has a write-what-where primitive but needs to achieve code execution. Which approach is most effective?
Select an answer first - 19
What is the primary purpose of Data Execution Prevention (DEP) on Windows?
Select an answer first - 20
An exploit developer is working on a Windows exploit where the primary buffer is too small to hold the full shellcode. However, a larger buffer is allocated elsewhere in memory and contains the shellcode. The exploit has a limited overwrite that can redirect execution. What technique should be used to locate and execute the shellcode?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GXPN” is a trademark of its owner, used for identification only.