
GIAC Defending Advanced Threats
Domain 2Objective 1
Installation GDAT Practice Questions (Page 5)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 21–25
- 21
An operator is downloading a post-exploitation tool from a vendor's website. The website offers a checksum file alongside the installer. What should the operator do to verify the download?
Select an answer first - 22
After installing a post-exploitation agent on a Linux host, the operator runs a test command but receives no output. The agent process is running. What should the operator check first?
Select an answer first - 23
During deployment of a post-exploitation tool, which practice best helps avoid detection while maintaining stability?
Select an answer first - 24
A penetration tester is setting up a Linux-based C2 server that must accept inbound connections from beacons on a segmented network. The tester has configured the listener and firewall, but beacons cannot connect. Which troubleshooting step should be performed first?
Select an answer first - 25
After installing a persistence mechanism on a Windows domain controller, an operator wants to confirm it will survive a reboot. Which action provides the most reliable verification?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.