
GIAC Red Team Professional
Domain 3Objective 2
Leveraging the Domain GRTP Practice Questions (Page 7)
Part of the Active Directory Attacks and Post-Exploitation domain, which makes up ~33% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~23–40 in this domain), expect 8–13 from this objective — we provide 65 practice questions to prepare you well beyond it. (estimate)
65questions here
13free pages
25concepts
Questions 31–35
- 31
What is ACL-based persistence in Active Directory?
Select an answer first - 32
During an engagement, you have obtained a low-privileged domain account. Your goal is to gain access to a service account that runs a legacy application. You have identified that the service account has an SPN registered. Which technique would most likely allow you to obtain the service account's password hash for offline cracking?
Select an answer first - 33
You have compromised an account that has the ability to create and link GPOs in the domain. You need to execute a command on all workstations in a specific organizational unit (OU). Which approach is most effective?
Select an answer first - 34
What is the primary purpose of a Golden Ticket attack?
Select an answer first - 35
You have compromised a service account that is configured for constrained delegation to a file server. You need to access the file server as a domain administrator. Which technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.