
GIAC AI Security Automation Engineer
Domain 3Objective 2
Adversary Emulation Fundamentals GASAE Practice Questions (Page 3)
Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 11–15
- 11
An emulation team is building a scenario based on a threat intelligence report that describes an adversary using PowerShell to download a payload, then creating a scheduled task for persistence, and finally exfiltrating data over HTTPS. The team wants to structure the emulation so that each step can be mapped to a specific detection opportunity. Which approach should they take?
Select an answer first - 12
An adversary emulation engagement has ended, and the team is preparing the final report. The report will be shared with both technical staff and senior management. The team wants to ensure that the report drives action and is understood by both audiences. What is the best approach for structuring the report?
Select an answer first - 13
During an emulation, the team needs to execute a technique that requires administrative privileges on a target Windows server. The team has credentials for a standard user account but not for an administrator. The rules of engagement allow privilege escalation as long as it does not affect other systems. What is the best course of action?
Select an answer first - 14
A company has a mature security program and wants to test its detection and response capabilities against a specific threat actor. The company also wants to minimize the risk of the emulation being detected by the SOC, because they want to test the SOC's ability to detect an actual attack. However, the legal team requires full transparency and approval of all actions. What is the best way to reconcile these conflicting requirements?
Select an answer first - 15
After an adversary emulation, the security team finds that a detection rule fired, but the alert was not investigated by the SOC because it was a low-priority alert. The team wants to improve the response process. What is the most effective improvement to recommend?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.