
GIAC Red Team Professional
Domain 2Objective 3
Enumerating and Attacking Privileges GRTP Practice Questions (Page 4)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
4concepts
Questions 16–20
- 16
You discover a Windows service that runs with SYSTEM privileges but has a weak file permission that allows your current user to modify the service's binary path. What is the most direct way to escalate privileges?
Select an answer first - 17
You have compromised a service account that has the 'SeImpersonatePrivilege' enabled. You want to escalate privileges to SYSTEM on a Windows server. Which tool or technique would you use to exploit this privilege?
Select an answer first - 18
During a privilege escalation attempt, an attacker discovers that the current user has the SeImpersonatePrivilege enabled. Which well-known attack vector does this privilege enable?
Select an answer first - 19
During privilege enumeration on a Windows target, which native command-line tool is used to display detailed information about the current user's group memberships and the privileges assigned to those groups?
Select an answer first - 20
You are on a Linux host and need to enumerate which commands your current user can run with sudo. Which command would you use to list the sudo permissions for your user?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.