
GIAC Defending Advanced Threats
Domain 2Objective 3
Active Directory/Domains GDAT Practice Questions (Page 3)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
Questions 11–15
- 11
You have compromised a domain-joined Windows 10 workstation and have local administrator privileges. You want to move laterally to a file server that uses the same local administrator password as the workstation. Which technique is most efficient?
Select an answer first - 12
Which tool is commonly used to extract credentials from memory on a Windows system?
Select an answer first - 13
You have compromised a domain user account and want to access a service that is configured to use Kerberos with AES256 encryption. You have the user's NTLM hash. Which technique is most likely to succeed?
Select an answer first - 14
During an engagement, you discover that a member server running an outdated application responds to NTLM authentication requests and has SMB signing disabled. You have a foothold on a workstation in the same subnet. You want to move laterally to the member server without knowing its local administrator password. Which technique is most appropriate?
Select an answer first - 15
You have compromised a domain controller and dumped the KRBTGT hash. You want to maintain access to the domain even if the current domain admin password is changed. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.