GIAC Defending Advanced Threats - GDAT Exam Practice Test
Which of the following are indicators of a potential HTTP-based data exfiltration?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: A,C
Vote an answer
Which method involves embedding a payload within innocent-looking files to bypass security filters?
Response:
Response:
Correct Answer: B
Vote an answer
What is the primary purpose of using a rootkit in malware installation?
Response:
Response:
Correct Answer: B
Vote an answer
Which step is critical in the initial phase of an incident response process?
Response:
Response:
Correct Answer: C
Vote an answer
What are key indicators of lateral movement within a network?
(Choose Three)
Response:
(Choose Three)
Response:
Correct Answer: A,B,D
Vote an answer
Your security team has identified unusual outbound traffic from your organization's network to external IP addresses. Upon further analysis, the traffic consists of a high volume of encrypted HTTP POST requests, with some payloads resembling legitimate DNS queries.
What is the most likely method of data exfiltration being used, and how should you proceed?
Response:
What is the most likely method of data exfiltration being used, and how should you proceed?
Response:
Correct Answer: C
Vote an answer
Which tool is commonly used during the reconnaissance phase to scan for open ports and services on a network?
Response:
Response:
Correct Answer: D
Vote an answer
Which of the following scenarios exemplifies a breach of the principle of least privilege?
Response:
Response:
Correct Answer: B,C
Vote an answer
What are essential components of a Kerberos-based authentication system in Active Directory?
Response:
Response:
Correct Answer: A,D
Vote an answer
Which of the following are signs of a successful payload delivery?
(Choose Two)
Response:
(Choose Two)
Response:
Correct Answer: A,D
Vote an answer
Which operating system features can be exploited by attackers to execute malicious payloads?
(Choose two)
Response:
(Choose two)
Response:
Correct Answer: B,D
Vote an answer
Which of the following methods is commonly used for delivering malicious payloads in phishing attacks?
Response:
Response:
Correct Answer: A
Vote an answer
Which of the following are common tools used in adversary emulation exercises?
(Choose two)
Response:
(Choose two)
Response:
Correct Answer: C,D
Vote an answer