
GIAC AI Security Automation Engineer
Domain 3Objective 2
Adversary Emulation Fundamentals GASAE Practice Questions (Page 8)
Part of the AI and Adversary Emulation domain, which makes up ~19% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~13–23 in this domain), expect 7–12 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
Questions 36–40
- 36
An emulation team is preparing to test a detection for credential dumping. They plan to use the Mimikatz tool to extract credentials from memory on a lab Windows host. Which MITRE ATT&CK technique ID should they reference in their test plan?
Select an answer first - 37
During an adversary emulation, the team needs to execute a technique that involves modifying the Windows registry to establish persistence. The lab environment is a replica of production, and the team wants to avoid leaving any traces that could affect future tests. What is the best practice for executing this technique?
Select an answer first - 38
A security team is asked to validate whether their detection stack can identify a specific nation-state actor's known TTPs. The team has a limited budget and cannot disrupt production. They also need to provide evidence to the board that the security controls work. Which approach best balances these constraints?
Select an answer first - 39
Which tool is commonly used for executing adversary emulation activities?
Select an answer first - 40
Which statement correctly distinguishes adversary emulation from penetration testing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GASAE” is a trademark of its owner, used for identification only.