
GIAC Defending Advanced Threats
Domain 2Objective 3
Active Directory/Domains GDAT Practice Questions (Page 4)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
Questions 16–20
- 16
In the Kerberos authentication flow, what does the client request from the Authentication Server (AS) to begin the process?
Select an answer first - 17
You are performing an NTLM relay attack. You have captured an NTLMv2 hash from a client that is attempting to authenticate to a web server. You want to relay this hash to a different server that has SMB signing disabled. Which condition is necessary for the relay to succeed?
Select an answer first - 18
In an NTLM relay attack, what is the attacker's primary goal?
Select an answer first - 19
Which Active Directory object is used to group users, groups, and computers for the purpose of delegating administrative permissions without creating a new domain?
Select an answer first - 20
You have compromised a domain user account that has 'Create Scheduled Tasks' permission on a target server. You want to execute a command on that server as SYSTEM. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.