Free GXPN sample questions
Real questions from the GIAC Exploit Researcher and Advanced Penetration Tester practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A penetration tester is attempting to exploit a heap-based vulnerability in a Linux service. The service forks a new process for every incoming connection. The tester suspects a stack canary (SSP) is in place, as the application crashes with "*** stack smashing detected ***" when the buffer is overflowed. Which technique is most appropriate to bypass the stack canary in this specific forking server scenario?
You are developing an exploit for a Windows application compiled with SafeSEH. You have control over the stack and can overwrite the SEH record, but you need a valid `pop pop ret` gadget to redirect execution to your shellcode. Which condition must be met for a `pop pop ret` gadget to be usable in a SafeSEH environment?
Which Windows 10 exploit mitigation mechanism validates indirect calls by checking a target address against a bitmap of valid function entry points before execution, effectively breaking most standard ROP chains that rely on arbitrary gadgets?
A penetration tester has obtained user-level access to a Windows workstation protected by AppLocker in 'Enforce' mode. The Default Rule is enabled, blocking all executables in non-standard directories. The tester needs to execute a custom C# payload. Which 'Living off the Land' binary could be used to bypass AppLocker by executing the payload contained within a specially crafted `.log` or `.txt` file via the `Uninstall` method?
A security analyst is testing a Windows environment where PowerShell is configured in Constrained Language Mode (CLM). The analyst attempts to run a script that utilizes .NET reflection to load a DLL into memory but receives an error stating the type cannot be created. What is the primary technical reason this script fails in CLM?
You are performing a physical penetration test and encounter a network port secured with 802.1X. You have a physical device that can bridge connections. You disconnect the victim PC, connect your bridge device to the wall, and connect the victim PC to the bridge. You wait for the victim to authenticate. Once the victim authenticates, what specific action must your attack device take to successfully piggyback on the session without triggering a port security violation?
A penetration tester is connected to a switch port assigned to VLAN 10 (Native VLAN 1). The tester wishes to reach a target server on VLAN 20. The switch is configured with 802.1Q trunking to an upstream switch. Which technique involves crafting a packet with two VLAN tags, where the first tag matches the native VLAN of the trunk, allowing the packet to be stripped of the first tag and forwarded to the second VLAN on the next switch?
You are auditing a network that uses HSRP (Hot Standby Router Protocol) for gateway redundancy. You discover that HSRP authentication is set to the default cleartext password 'cisco'. You launch an attack to become the active router. After successfully injecting a higher priority HSRP packet and becoming the Active router, what critical step must be taken to ensure traffic still reaches the internet and the users do not experience a denial of service?
Which of the following routing protocol attacks allows an attacker to inject a false route into an OSPF area by establishing a full adjacency with a legitimate neighbor, often requiring knowledge or cracking of the MD5 authentication key?
10 more free samples are waiting
Create a free account to unlock the whole GXPN sample bank, or get full access to all 218 practice questions in the simulator.