GIAC Defending Advanced Threats Sample Questions:
1. The tool commonly used for automated penetration testing that simulates an attack from the attacker's perspective is called _________.
Response:
A) Snort
B) Wireshark
C) Nessus
D) Metasploit
2. What is the primary benefit of using encryption during data exfiltration?
Response:
A) It enhances system performance
B) It prevents detection by masking the content of the exfiltrated data
C) It ensures compliance with GDPR regulations
D) It allows attackers to bypass firewalls
3. What is a common method by which malware ensures its persistence on a host system after reboot?
Response:
A) Deleting system logs
B) Modifying user profiles
C) Adding entries to the Windows Registry
D) Registering a new user account
4. Your organization has recently integrated threat modeling into its SDLC. During the design phase of a new application, a security flaw was identified related to insufficient encryption of sensitive user data.
As a security engineer, what steps should you prioritize to remediate this issue before the application moves into the implementation phase?
Response:
A) Delay the project timeline to allow for a full security audit of the application
B) Develop a separate encryption tool to be added post-deployment
C) Implement a strong encryption algorithm for sensitive data during transmission and storage
D) Ignore the issue as it can be addressed in a later phase with a security patch
5. Which step is critical in the initial phase of an incident response process?
Response:
A) Communication with the media
B) Identification of the breach
C) Cost analysis of the incident
D) Purchasing new security tools
Solutions:
| Question # 1 Answer: D | Question # 2 Answer: B | Question # 3 Answer: C | Question # 4 Answer: C | Question # 5 Answer: B |
We're so confident of our products that we provide no hassle product exchange.


By Erica

