Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 54 pages
Exam (elaborations)

GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 4 out of 54 pages

GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Content preview

GIAC Exploit Researcher and Advanced
Penetration Tester (GXPN) Questions And
Correct Answers (Verified Answers) Plus
Rationales 2026 Q&A | Instant Download Pdf


1. Which type of vulnerability allows an attacker to overwrite a
program’s memory beyond the intended boundary of a buffer?

A. SQL Injection
B. Cross-Site Scripting
C. Buffer Overflow
D. Directory Traversal

Answer: C. Buffer Overflow

Rationale: A buffer overflow occurs when a program writes more data
into a buffer than it was designed to hold. This excess data can
overwrite adjacent memory locations, potentially altering program
execution and allowing attackers to inject and execute malicious code.

, 2. Which CPU register typically contains the address of the next
instruction to be executed?

A. EAX
B. ESP
C. EIP
D. EDX

Answer: C. EIP

Rationale: The Extended Instruction Pointer (EIP) register in x86
architecture holds the memory address of the next instruction to
execute. Control of EIP is often the primary goal during exploit
development because redirecting it allows execution of attacker-
controlled code.



3. What is the primary purpose of shellcode in exploit development?

A. Encrypting network traffic
B. Executing arbitrary instructions on the target system
C. Generating passwords
D. Compressing payloads

Answer: B. Executing arbitrary instructions on the target system

,Rationale: Shellcode is a small piece of machine code used as a
payload in exploitation. Once execution control is obtained, shellcode
performs actions such as spawning a shell, creating reverse
connections, or executing commands.



4. What does ASLR stand for?

A. Address Space Layout Randomization
B. Application Security Layer Routing
C. Automated Security Logging Routine
D. Advanced System Link Registry

Answer: A. Address Space Layout Randomization

Rationale: ASLR randomizes memory address locations used by system
and application processes. This prevents attackers from predicting
memory addresses required for successful exploitation.



5. What technique allows attackers to execute code by chaining
together small snippets of existing code in memory?

A. Heap spraying
B. Return-Oriented Programming

, C. Cross-site scripting
D. Port scanning

Answer: B. Return-Oriented Programming

Rationale: Return-Oriented Programming (ROP) bypasses protections
such as NX by chaining short instruction sequences called gadgets that
already exist in executable memory.



6. What protection mechanism marks memory regions as non-
executable?

A. DEP
B. TLS
C. DNSSEC
D. SMB

Answer: A. DEP

Rationale: Data Execution Prevention (DEP) prevents execution of code
from memory regions marked as data-only. Attackers must bypass DEP
to run injected shellcode.

Document information

Uploaded on
March 23, 2026
Number of pages
54
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
LectRizz
3.6
(27)
Sold
107
Followers
1
Items
4069
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions