
GIAC Defending Advanced Threats
Domain 2Objective 2
Lateral Movement GDAT Practice Questions (Page 2)
Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)
42questions here
9free pages
4concepts
Questions 6–10
- 6
A company is implementing network segmentation to limit lateral movement. The security team wants to ensure that a compromised workstation cannot reach the domain controllers. Which control is the most effective?
Select an answer first - 7
A penetration tester is attempting to move laterally in a Windows environment. They have obtained a Kerberos ticket for a user and want to use it to access a web server. Which tool or method would be most appropriate?
Select an answer first - 8
How can network traffic analysis help detect lateral movement?
Select an answer first - 9
A company wants to limit the blast radius of a compromised domain admin account. The security team proposes implementing tiered administration, but the IT director is concerned about the operational overhead of managing multiple admin accounts. Which approach best balances security and operational overhead?
Select an answer first - 10
A company is implementing a least-privilege model to limit lateral movement. The security team wants to ensure that users only have access to the resources they need. Which approach is the most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.