Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Red Team Professional

Domain 3Objective 2

Leveraging the Domain GRTP Practice Questions (Page 11)

Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)

65questions here
13free pages
25concepts

Questions 51–55

  1. 51foundation · easy

    What is required to forge a Golden Ticket?

    Select an answer first
  2. 52application · medium

    You are enumerating a domain and find an account with the 'Do not require Kerberos preauthentication' flag set. You have network access to a domain controller but no valid credentials. What is the most effective way to obtain a crackable hash for this account?

    Select an answer first
  3. 53application · medium

    You have administrative credentials for a remote Windows server that has WinRM enabled. You need to execute a PowerShell command on the server. Which technique is most appropriate?

    Select an answer first
  4. 54expert · hard

    You have Domain Admin privileges and want to maintain access to the domain even if the KRBTGT password is changed. You also want to avoid rebooting the domain controller. Which technique is most appropriate?

    Select an answer first
  5. 55foundation · easy

    Which service does PsExec typically install on the remote system to execute commands?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.