
GIAC Red Team Professional
Domain 3Objective 1
Attacking Active Directory GRTP Practice Questions (Page 5)
Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 61 practice questions to prepare you well beyond it. (estimate)
61questions here
13free pages
19concepts
Questions 21–25
- 21
You have compromised a domain user in a child domain and need to move laterally to a server in the parent domain. The trust relationship is a two-way transitive trust. Which technique is most appropriate?
Select an answer first - 22
Which type of delegation allows a service to impersonate users to any service in the domain?
Select an answer first - 23
You have compromised a workstation and obtained the NTLM hash of a domain user. The user has local admin rights on a target server that only allows Kerberos authentication (NTLM is disabled). You need to move laterally to the target server. Which technique should you use?
Select an answer first - 24
Which type of trust is automatically created between a parent and child domain in the same forest?
Select an answer first - 25
You have compromised an account that has the 'Replicating Directory Changes' and 'Replicating Directory Changes All' permissions on the domain. You need to extract password hashes for all users without logging into any domain controller. Which technique should you use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.