
GIAC Information Security Fundamentals
Domain 3Objective 3
Post-Exploitation and Advanced Threat Techniques GISF Practice Questions (Page 4)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 16–20
- 16
An incident response team is analyzing a breach where the attacker gained access to a web server, then used the compromised server to access an internal database, and finally exfiltrated data via encrypted FTP. The team needs to determine the attacker's post-exploitation phases. Which sequence of phases is MOST accurate?
Select an answer first - 17
An attacker with a standard user account exploits a vulnerability to gain SYSTEM-level privileges on a Windows host. This is an example of which type of privilege escalation?
Select an answer first - 18
A security team wants to reduce the risk of post-exploitation activities on their Windows workstations. They cannot replace the operating systems or deploy new agents. Which control is MOST effective in limiting persistence and privilege escalation?
Select an answer first - 19
A security analyst notices that a compromised server is sending large volumes of data to a cloud storage service that the organization does not use. The traffic is encrypted and occurs during off-peak hours. Which defensive measure would be MOST effective in detecting this activity?
Select an answer first - 20
What is the primary role of a command and control (C2) channel in post-exploitation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.