Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Foundational Cybersecurity Technologies

Domain 6Objective 2

Forensics & Post-Exploitation GFACT Practice Questions (Page 6)

Part of the Offensive Security and Defense domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 26–30

  1. 26foundation · easy

    An attacker wants to ensure that a malicious program runs automatically every time a user logs into a Windows system. Which persistence mechanism is commonly used for this purpose?

    Select an answer first
  2. 27application · medium

    An incident responder needs to analyze a compromised Linux server to determine if an attacker exfiltrated data via HTTP POST requests. The server is still running, and the responder wants to preserve volatile evidence before shutting it down. Which tool should be used first?

    Select an answer first
  3. 28expert · hard

    A security analyst is investigating a data breach where sensitive files were exfiltrated from a corporate network. The analyst finds that the attacker used a legitimate cloud storage service to upload the files. Which detection method would be most effective in identifying this type of exfiltration?

    Select an answer first
  4. 29application · medium

    A penetration tester successfully gains initial access to a Windows server via a vulnerable web application. The tester needs to ensure access remains available even if the server is rebooted. Which action would best achieve persistence while minimizing the chance of immediate detection?

    Select an answer first
  5. 30application · medium

    An attacker has compromised a domain user's workstation and captured the user's password hash. The attacker wants to access a file server that uses the same domain credentials. Which technique would allow the attacker to authenticate to the file server without knowing the plaintext password?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.