Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 2Objective 3

Active Directory/Domains GDAT Practice Questions (Page 4)

Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
10concepts

Questions 16–20

  1. 16foundation · easy

    In the Kerberos authentication flow, what does the client request from the Authentication Server (AS) to begin the process?

    Select an answer first
  2. 17expert · hard

    You are performing an NTLM relay attack. You have captured an NTLMv2 hash from a client that is attempting to authenticate to a web server. You want to relay this hash to a different server that has SMB signing disabled. Which condition is necessary for the relay to succeed?

    Select an answer first
  3. 18foundation · easy

    In an NTLM relay attack, what is the attacker's primary goal?

    Select an answer first
  4. 19foundation · easy

    Which Active Directory object is used to group users, groups, and computers for the purpose of delegating administrative permissions without creating a new domain?

    Select an answer first
  5. 20application · medium

    You have compromised a domain user account that has 'Create Scheduled Tasks' permission on a target server. You want to execute a command on that server as SYSTEM. Which technique is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.