
GIAC Red Team Professional
Domain 2Objective 3
Enumerating and Attacking Privileges GRTP Practice Questions (Page 6)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 41 practice questions to prepare you well beyond it. (estimate)
41questions here
9free pages
4concepts
Questions 26–30
- 26
You have a shell as a user with the `SeImpersonatePrivilege` on a Windows host, but the host is running an EDR that blocks known token impersonation tools like JuicyPotato and PrintSpoofer. What is the most effective way to escalate to SYSTEM while avoiding detection?
Select an answer first - 27
You have a foothold on a Windows host and need to identify services that might be misconfigured for privilege escalation. Which command or tool would be most effective for this purpose?
Select an answer first - 28
You have a low-privilege shell on a Linux host. Enumeration shows that the current user can write to a directory that is in the PATH for a cron job running as root. What is the most effective way to escalate privileges?
Select an answer first - 29
After enumerating privileges on a Linux target, you find that your user can run 'sudo -l' and see that you can execute '/usr/bin/vim' as root without a password. What is the most efficient way to escalate to a root shell?
Select an answer first - 30
You are on a Linux host and have found that your user can run 'sudo /usr/bin/python3' as root. You need to escalate to a root shell, but the environment has a restrictive AppArmor profile that prevents python3 from executing subprocesses. Which technique would you use to escalate privileges?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.