
GIAC Red Team Professional
Domain 3Objective 2
Leveraging the Domain GRTP Practice Questions (Page 5)
Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
25concepts
Questions 21–25
- 21
Which permission on a user object would allow an attacker to reset that user's password?
Select an answer first - 22
During an assessment, you have successfully dumped a TGT from the memory of a domain user's workstation. You need to access a file share on a remote server as that user. Which technique should you use?
Select an answer first - 23
You have compromised a workstation and extracted the NTLM hash of a domain admin account. You need to move laterally to a file server that does not support Kerberos. Which technique should you use?
Select an answer first - 24
What is needed to extract password hashes from NTDS.dit?
Select an answer first - 25
What is NTDS.dit?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.