
GIAC Information Security Fundamentals
Domain 3Objective 3
Post-Exploitation and Advanced Threat Techniques GISF Practice Questions (Page 5)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 21–25
- 21
A penetration tester has compromised a standard user account on a Windows domain. The tester wants to gain domain administrator privileges. Which approach is an example of vertical privilege escalation?
Select an answer first - 22
During an incident response, you find that an attacker used the built-in Windows tool `wmic` to query running processes on multiple workstations from a single compromised server. The attacker did not install any additional tools on the workstations. Which post-exploitation phase does this activity represent?
Select an answer first - 23
A security team is designing a defense-in-depth strategy to mitigate post-exploitation activities. They have limited budget and cannot deploy new agents. They need to prioritize controls that address persistence, privilege escalation, and lateral movement. Which combination of controls would be MOST effective?
Select an answer first - 24
Which of the following techniques is commonly used for lateral movement in a Windows environment?
Select an answer first - 25
What is the difference between vertical and horizontal privilege escalation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.