Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC AI Security Automation Engineer

Domain 3Objective 2

Adversary Emulation Fundamentals GASAE Practice Questions (Page 1)

Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)

49questions here
10free pages
7concepts

Questions 1–5

  1. 1application · medium

    A threat intelligence report indicates that a particular adversary group typically uses a specific remote access tool (RAT) and a unique domain generation algorithm (DGA) for C2. The emulation team wants to validate their network detections for this group. What is the most realistic approach?

    Select an answer first
  2. 2foundation · easy

    An organization wants to test its security controls by having a team mimic the specific behaviors of a known threat group, using the same tools and techniques that group is known to use. Which activity best describes this approach?

    Select an answer first
  3. 3application · medium

    A security team is asked to validate whether their SIEM detections would fire against a specific ransomware group that has been observed using living-off-the-land binaries and scheduled tasks for persistence. The team wants to simulate that group's behavior without causing disruption to production systems. Which approach best matches this requirement?

    Select an answer first
  4. 4application · medium

    An intelligence report describes an adversary that uses spear-phishing emails with malicious Office documents, then employs PowerShell to download additional tools, and finally uses scheduled tasks for persistence. The emulation team needs to structure their playbook to align with industry-standard terminology. Which mapping should they use?

    Select an answer first
  5. 5expert · hard

    A security team is asked to test the organization's ability to detect a specific threat actor. The team has a threat intelligence report that describes the actor's TTPs. However, the report is based on a single incident and may not be fully representative of the actor's behavior. The team must decide how to proceed. What is the best approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.