GIAC Defending Advanced Threats - GDAT 模擬練習
What is the role of PowerShell in the context of payload execution?
Response:
Response:
正解: B
Which of the following are common techniques used by attackers for lateral movement?
(Choose two)
Response:
(Choose two)
Response:
正解: A,C
What is the primary goal of integrating threat modeling into the software development lifecycle?
Response:
Response:
正解: C
Which of the following exemplifies a breach of the principle of least privilege?
(Choose two)
Response:
(Choose two)
Response:
正解: B,D
Your organization has been noticing a spike in helpdesk tickets from users who cannot access network resources. After conducting an investigation, you discover that multiple users' sessions have expired unexpectedly. Additionally, a network scan reveals a high number of Kerberos tickets with unusually extended lifetimes.
What action should you prioritize to investigate and mitigate this issue?
Response:
What action should you prioritize to investigate and mitigate this issue?
Response:
正解: C
What is the significance of analyzing Windows event logs in the context of detecting lateral movement?
Response:
Response:
正解: C
Which security practices help detect and mitigate persistence threats in an organization?
(Choose Three)
Response:
(Choose Three)
Response:
正解: A,B,D
Select the methods that can help in detecting Golden Ticket attacks on Active Directory environments.
Response:
Response:
正解: C,D
What technique is commonly used to deliver payloads in a phishing attack?
Response:
Response:
正解: B
Which strategies are effective in preventing privilege escalation attacks?
Response:
Response:
正解: B,C
Which of the following is a key technical control that should be considered when conducting adversary emulation?
Response:
Response:
正解: C
Which of the following actions are effective in mitigating the risk of Kerberos ticket replay attacks?
Response:
Response:
正解: A,B
What is a common payload execution technique used by malware after initial infection?
Response:
Response:
正解: D
In the context of access controls, which mechanism is primarily used to enforce least privilege?
Response:
Response:
正解: D
Which of the following best describes threat modeling in the context of application security?
Response:
Response:
正解: A