
GIAC Defending Advanced Threats
Domain 2Objective 3
Active Directory/Domains GDAT Practice Questions (Page 1)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
Questions 1–5
- 1
Which protocol is commonly targeted in an NTLM relay attack to gain access to resources?
Select an answer first - 2
You are assessing a new client's Active Directory environment. You discover that the 'Domain Admins' group is a member of the local 'Administrators' group on all domain-joined servers. Which security implication is most accurate?
Select an answer first - 3
What is a domain trust relationship?
Select an answer first - 4
You have gained write access to a Group Policy Object that applies to a set of servers. You want to achieve remote code execution on those servers without directly modifying local services or creating new domain accounts. Which GPO setting is most appropriate?
Select an answer first - 5
You have compromised a workstation in a domain and have domain user credentials. You want to identify all paths to domain admin. Which tool is most appropriate for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.