
GIAC Red Team Professional
Domain 2Objective 3
Enumerating and Attacking Privileges GRTP Practice Questions (Page 1)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
4concepts
Questions 1–5
- 1
You have a shell as a user with the `SeBackupPrivilege` enabled on a Windows host. What is the most effective way to escalate privileges?
Select an answer first - 2
During post-enumeration exploitation, an attacker finds that the current user can write to a directory that is in the PATH of a service running as SYSTEM. Which attack step is most appropriate?
Select an answer first - 3
You have a shell as a service account on a Windows host. You notice the account has the `SeImpersonatePrivilege` enabled. Which tool or technique would you use to escalate to SYSTEM?
Select an answer first - 4
You have a low-privilege shell on a Linux host. You find that the `sudoers` file allows the current user to run `/usr/bin/less` as root without a password. However, the system has `sudo` configured with `requiretty` and the `secure_path` option. What is the most effective way to escalate privileges?
Select an answer first - 5
Which privilege abuse technique involves stealing or reusing an access token from another process to gain the privileges of that process's user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.