Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Defending Advanced Threats

Domain 2Objective 2

Lateral Movement GDAT Practice Questions (Page 5)

Part of the Post-Exploitation and Movement domain, which makes up ~29% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–23 in this domain), expect 5–8 from this objective — we provide 42 practice questions to prepare you well beyond it. (estimate)

42questions here
9free pages
4concepts

Questions 21–25

  1. 21application · medium

    A security analyst is tuning detection rules for lateral movement. They notice that a legitimate admin tool creates remote scheduled tasks on multiple servers as part of normal operations. Which approach would best reduce false positives while still detecting malicious lateral movement?

    Select an answer first
  2. 22application · medium

    A company wants to reduce the risk of lateral movement via pass-the-hash. The security team is considering several controls. Which control is most directly effective against pass-the-hash?

    Select an answer first
  3. 23application · medium

    A security analyst notices that a compromised workstation is using cached credentials to authenticate to a file server, and the analyst wants to prevent the attacker from reusing those credentials to move to other systems. The environment uses Kerberos with RC4 encryption enabled for legacy compatibility. Which configuration change would most directly limit this lateral movement technique?

    Select an answer first
  4. 24application · medium

    A SOC analyst is investigating a potential lateral movement incident. They see a series of RDP connections from a compromised workstation to multiple servers, but the user account used is a standard user with no administrative rights. Which detection method would be most effective in identifying this as malicious?

    Select an answer first
  5. 25application · medium

    A security team is reviewing their detection capabilities for lateral movement. They want to identify a technique that can detect pass-the-hash attacks by analyzing authentication events. Which data source would be most useful?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GDAT” is a trademark of its owner, used for identification only.