
GIAC Information Security Fundamentals
Domain 3Objective 3
Post-Exploitation and Advanced Threat Techniques GISF Practice Questions (Page 6)
Part of the Threats and Defenses domain, which makes up ~36% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~18–29 in this domain), expect 5–7 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
9concepts
Questions 26–30
- 26
Which of the following is a defensive measure to mitigate lateral movement?
Select an answer first - 27
Which of the following is a defensive measure that can help detect post-exploitation activities?
Select an answer first - 28
A security team is investigating a host that is using the built-in Windows tool 'wmic' to query system information and 'schtasks' to create scheduled tasks on remote systems. The team has limited visibility into command-line arguments. Which additional data source would provide the MOST useful information for detecting this activity?
Select an answer first - 29
A threat actor has compromised a Linux server and is using `ssh`, `scp`, and `curl` to move data to an external server. The security team's EDR does not flag these activities because they are performed by legitimate system binaries. Which defensive technique would be MOST effective in detecting this behavior?
Select an answer first - 30
An incident responder discovers that an attacker used a compromised domain admin account to connect to multiple servers and create new local admin accounts. The attacker then used those local accounts to access other servers. Which post-exploitation technique is the attacker using, and what is the PRIMARY defensive concern?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GISF” is a trademark of its owner, used for identification only.