
GIAC Defending Advanced Threats
Domain 2Objective 1
Installation GDAT Practice Questions (Page 9)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 43 practice questions to prepare you well beyond it. (estimate)
43questions here
9free pages
5concepts
Questions 41–43
- 41
An operator is installing a post-exploitation tool from source code on a Linux server. The source code is downloaded from a GitHub repository that has been archived by the original author. The operator wants to ensure the code has not been tampered with since the author archived it. Which step is most reliable?
Select an answer first - 42
An operator is installing a post-exploitation agent on a Windows host that has Application Control (AppLocker) enabled, allowing only signed executables. The operator has a signed binary that is not the agent. Which technique would allow the agent to run without triggering AppLocker?
Select an answer first - 43
A red-team engagement requires installing a post-exploitation agent on a highly monitored Windows server. The SOC monitors process creation, network connections, and file writes. The agent must maintain stealth and provide interactive access. The operator has local admin rights but cannot install a kernel driver. Which approach best balances stealth and functionality?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GDAT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.