
GIAC Red Team Professional
Domain 3Objective 2
Leveraging the Domain GRTP Practice Questions (Page 6)
Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
25concepts
Questions 26–30
- 26
You have compromised a child domain and want to gain access to resources in a parent domain. You have the KRBTGT hash of the child domain. Which technique is most effective?
Select an answer first - 27
Why does password spraying use a small number of passwords?
Select an answer first - 28
You are performing an internal assessment and have a low-privileged domain account. You need to identify accounts that are vulnerable to AS-REP roasting. Which initial step is most effective?
Select an answer first - 29
Which permission is required to perform a DCSync attack?
Select an answer first - 30
What is the purpose of the AdminSDHolder object in Active Directory?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.