
GIAC Defending Advanced Threats
Domain 2Objective 3
Active Directory/Domains GDAT Practice Questions (Page 6)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
10concepts
Questions 26–30
- 26
You have compromised a domain admin account and want to maintain persistence even if the domain admin password is changed. You decide to modify the adminSDHolder object. Which effect does this have?
Select an answer first - 27
What is the purpose of the 'pass-the-hash' attack?
Select an answer first - 28
You have compromised a domain user account that has the 'Replicating Directory Changes' permission. You want to escalate to domain admin without triggering immediate detection. Which technique is most appropriate?
Select an answer first - 29
A red teamer has compromised the krbtgt account hash of a domain. They want to maintain access to the domain for an extended period without being detected by periodic password changes of user accounts. Which persistence mechanism is most appropriate?
Select an answer first - 30
During an assessment, you discover that a domain user account has the 'Replicating Directory Changes' permission on the domain. You want to escalate to domain admin. Which technique is most directly enabled by this permission?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.