Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Foundational Cybersecurity Technologies

Domain 6Objective 2

Forensics & Post-Exploitation GFACT Practice Questions (Page 7)

Part of the Offensive Security and Defense domain, which makes up ~25% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 7–10 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
6concepts

Questions 31–35

  1. 31foundation · easy

    An attacker has stolen sensitive files and wants to send them to an external server while avoiding detection by content inspection. Which technique is commonly used to hide the content during exfiltration?

    Select an answer first
  2. 32expert · hard

    An attacker has compromised a workstation and obtained the NTLM hash of a domain admin. The attacker wants to access a file server and then exfiltrate sensitive documents. The file server has SMB signing enabled. Which technique would allow the attacker to authenticate and exfiltrate data while avoiding detection?

    Select an answer first
  3. 33application · medium

    After a ransomware incident, the incident response team has identified the entry point and removed the malware from all affected systems. The team now needs to restore systems from backups and verify that they are functioning normally. Which incident response phase does this represent?

    Select an answer first
  4. 34expert · hard

    A red team operator has compromised a Windows server and needs to maintain access for a long-term engagement. The operator also needs to exfiltrate data periodically without raising suspicion. The server is monitored by a SIEM that alerts on new services and scheduled tasks. Which persistence mechanism is least likely to trigger the SIEM while still allowing periodic data exfiltration?

    Select an answer first
  5. 35expert · hard

    A company has just experienced a ransomware attack. The incident response team has identified the initial entry point and has isolated the affected systems. The CEO wants to restore operations as quickly as possible, but the legal team insists on preserving evidence for potential litigation. Which action best balances the need for recovery with the need for evidence preservation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GFACT” is a trademark of its owner, used for identification only.