Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Red Team Professional

Domain 3Objective 1

Attacking Active Directory GRTP Practice Questions (Page 12)

Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)

61questions here
13free pages
19concepts

Questions 56–60

  1. 56application · medium

    You are mapping an Active Directory forest that contains multiple domains. You need to identify the boundaries of the forest and the trust relationships between domains to plan lateral movement. Which enumeration approach is most effective?

    Select an answer first
  2. 57application · medium

    During an internal penetration test, you have obtained a low-privileged domain user's credentials. You need to identify service accounts that are vulnerable to Kerberoasting without triggering a large number of failed logon events. Which approach is most appropriate?

    Select an answer first
  3. 58expert · hard

    You have compromised a domain controller and extracted the KRBTGT account hash. You want to maintain persistent access to the domain even after the compromised domain controller is rebuilt. You also want to avoid detection by creating a ticket that is valid for a long period. Which technique should you use?

    Select an answer first
  4. 59expert · hard

    You have compromised a domain controller and extracted the KRBTGT hash. You want to maintain access to the domain without triggering alerts that monitor for unusual TGT requests or logon events. Which technique should you use?

    Select an answer first
  5. 60expert · hard

    You have compromised a domain controller and extracted the KRBTGT hash. You want to maintain persistent access to the domain even after the compromised domain controller is rebuilt and the KRBTGT password is reset. Which approach is most effective for long-term persistence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.