GIAC · Free Practice Questions · Last reviewed May 2026
90real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An organization is migrating to AWS and needs to ensure that IAM users do not possess long-term credentials. Which approach provides the most secure mechanism for programmatic access?
Generate unique access keys for every developer stored in an encrypted S3 bucket.
Rotate IAM user access keys every 90 days via an automated script.
Implement IAM roles that grant temporary security credentials via STS.
IAM roles provide temporary security credentials that expire automatically, effectively mitigating the risk of credential theft. By leveraging AWS Security Token Service (STS), developers can assume roles only when needed. This approach eliminates the need for managing static keys, significantly reducing the attack surface for programmatic cloud access.
Use an IAM group policy to enforce Multi-Factor Authentication on all API requests.
When designing a secure cloud database, which configuration best protects against unauthorized data exfiltration if the database instance is misconfigured as public?
Setting a complex root password for the database.
Placing the database in a private subnet with restricted Security Group rules.
Private subnets lack a route to an Internet Gateway, effectively isolating the database from the public internet. Restricting Security Group rules to only accept traffic from specific application server subnets ensures that even internal access is highly controlled, significantly reducing the surface area for unauthorized data exfiltration attempts.
Enabling database logging for every query.
Using a public IP address for faster data synchronization.
Which of the following describes the 'Confused Deputy' problem in the context of cloud IAM roles?
A user is assigned two different roles with conflicting permissions.
A malicious user triggers a service to use its privileges against a resource.
This occurs when an attacker convinces a service that has sufficient permissions to act on their behalf. Without checks like External IDs, the service might unknowingly perform actions, such as reading private data, because it trusts the requester. This is a major security concern in multi-tenant cloud environments.
Two cloud administrators inadvertently delete each other's work.
A service fails to refresh its temporary tokens, causing a lockout.
Which feature is most effective for preventing the accidental upload of secrets to a public cloud source code repository?
Implementing a post-push webhook to scan the repository.
Using pre-commit hooks to scan code for patterns.
Pre-commit hooks catch secrets before they are committed to the local repository. This prevents sensitive data from ever reaching the remote server. It is a proactive, shift-left security control that empowers developers to fix mistakes locally, maintaining the integrity of the codebase and preventing accidental credential leakage effectively.
Enabling public repository visibility scanning.
Enforcing HTTPS for all Git operations.
Which security principle is violated when an IAM user is assigned the 'AdministratorAccess' policy for daily operational tasks?
Separation of Duties.
Principle of Least Privilege.
The Principle of Least Privilege requires that users be granted only the minimum permissions needed to complete a task. 'AdministratorAccess' provides broad, excessive permissions that are rarely required for daily operational tasks. Using such an account for routine work exposes the organization to unnecessary risk if the account is compromised.
Defense in Depth.
Security through Obscurity.
An incident responder discovers an EC2 instance in AWS has been compromised via a web application vulnerability. The instance profile attached to the instance has broad administrative permissions. What is the immediate priority to contain credential compromise in this scenario?
Terminate the compromised EC2 instance immediately to destroy any running malicious processes and volatile memory artifacts.
Attach a restrictive Network ACL to the subnet to block all inbound and outbound traffic originating from the compromised instance's private IP address.
Revoke active sessions using IAM boundary conditions and rotate or restrict the attached IAM instance profile role permissions.
Invalidating active temporary credentials and modifying the role policies stops ongoing unauthorized API access. This directly mitigates the risk of lateral movement across the cloud environment by cutting off the compromised instance profile's valid session tokens.
Modify the VPC route table to remove the internet gateway route, isolating the entire virtual private cloud from external communication.
Want more Securing Credentials and Data in Cloud practice?
Practice this domainRefer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?
The service has already been deleted by the system.
The 'sc' command does not support the 'binPath' argument.
The command syntax is incorrect for creating a service.
The 'sc query' command is designed to retrieve the status of a registered service, not to define a new one. To register a service, the attacker must use 'sc create [ServiceName] binPath=...'. The provided command failed because it was querying for an object that was never defined.
The user lacks sufficient privileges to query services.
An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?
Win32_Service, StartService
Win32_Process, Create
The Win32_Process Create method is a standard technique used by attackers to execute commands on remote systems via WMI. It is favored because it does not require a persistent installation, allowing for stealthy lateral movement that is easily integrated into automated post-exploitation scripts and tools.
Win32_StartupCommand, Create
Win32_ScheduledJob, Create
During an investigation, you observe an attacker using 'PsExec' to move laterally. What is the primary artifact created by PsExec that can be used to track its execution across the network?
The creation of a temporary file named 'psexec.exe' in the root directory.
The installation of a service named 'PSEXESVC'.
PsExec operates by deploying a service named 'PSEXESVC' to the remote machine. Monitoring for the registration and execution of this service is a standard and highly effective detection technique for responders. It is the core mechanism PsExec uses to achieve remote code execution as a system user.
An entry in the 'Run' registry key for persistence.
A specific user-mode process named 'psexec_agent'.
An attacker has compromised a Linux host and is pivoting using a SOCKS proxy. Which tool is most commonly utilized for this purpose in a cross-platform environment?
Netcat
Chisel
Chisel is highly effective for creating SOCKS proxies because it encapsulates traffic within HTTP/HTTPS, often bypassing basic firewall egress rules. Because it uses a client-server model, it allows attackers to easily tunnel arbitrary traffic through a compromised node, making it a critical tool to monitor.
Tcpdump
Wget
Why are 'Pass-the-Hash' (PtH) attacks effective for pivoting in a Windows environment?
Because they force a password reset on the target.
Because NTLM authentication does not require the password itself.
The NTLM authentication protocol is designed to verify identity using a challenge-response mechanism based on the user's hash. As long as the attacker has the valid hash, they can participate in the challenge-response process just like the legitimate user, gaining unauthorized access to the network resources.
Because they only work on Linux-based domain controllers.
Because the hash is always encrypted with AES-256.
Which of the following describes the 'SMB Relay' attack during lateral movement?
Encrypting files on the network share.
Intercepting authentication and relaying it to another machine.
This accurately describes the mechanism of an SMB Relay attack. By positioning themselves as a man-in-the-middle, the attacker captures the authentication handshake and forwards it to a destination server. This allows the attacker to authenticate as the victim, effectively pivoting to a new host without cracking passwords.
Sending flood packets to crash the SMB service.
Replacing the SMB.exe binary with a malicious version.
Want more Endpoint Attack and Pivoting practice?
Practice this domainAn incident handler observes that an internal server is leaking sensitive file system structure via SMB. Which configuration change most effectively prevents SMB null session enumeration?
Set RestrictAnonymous to 0
Enable SMBv1 protocol support
Set RestrictAnonymous to 2
Setting this registry value to 2 enforces the highest level of restriction by preventing anonymous users from enumerating shares or user accounts. This forces the SMB service to require authenticated sessions for all enumeration requests, thereby effectively neutralizing standard null session reconnaissance techniques often used by attackers during internal network post-exploitation.
Disable the LanmanServer service
Which TWO of the following are primary security risks associated with the SMBv1 protocol in a modern Windows environment?
Inability to support Kerberos authentication
Susceptibility to remote code execution via EternalBlue
SMBv1 was the vector for the infamous EternalBlue exploit, which allowed attackers to execute code remotely on vulnerable systems. This vulnerability remains a primary reason why security professionals advocate for the total removal of SMBv1, as it provides a reliable path for attackers to gain administrative control over systems.
Lack of support for SMB message signing
Increased risk of man-in-the-middle and relay attacks
SMBv1 is notoriously easy to exploit via relay attacks when signing is not strictly enforced. Attackers can intercept traffic, perform session hijacking, or relay authentication tokens to other resources on the network. This makes SMBv1 a major liability in any environment where network integrity and confidentiality are required.
Incompatibility with NTFS permissions
An organization experiences a rapid spread of ransomware across the internal network. Analysts determine that the ransomware is exploiting SMB to move laterally. Which configuration effectively limits this spread by preventing SMB communication between workstations?
Disabling the Workstation service on all servers
Implementing Windows Firewall rules to block port 445 between workstations
Restricting SMB traffic on port 445 between workstations is a standard security practice to prevent lateral movement. Since workstations rarely need to share files directly with one another, blocking this traffic effectively stops many automated worms and ransomware variants from propagating across the local network segment during an active incident.
Increasing the SMB session timeout duration
Enabling the Print Spooler service on all workstations
Which THREE actions are recommended to secure SMB against credential relay and man-in-the-middle attacks?
Enforce SMB message signing
SMB signing adds a cryptographic signature to each packet, ensuring that the traffic has not been modified in transit. This is a primary defense against man-in-the-middle attacks, as an attacker cannot forge or alter packets without the server detecting the invalid signature, effectively neutralizing the relay attack vector.
Force the use of SMBv1 exclusively
Implement SMB encryption
SMB encryption, introduced in newer versions of the protocol, ensures that sensitive data is protected from eavesdropping. Beyond confidentiality, it forces a secure channel that is inherently more resistant to tampering than plaintext SMB sessions, providing an essential layer of security for traffic traversing across untrusted or sensitive network segments.
Disable the SMBv1 protocol
Disabling SMBv1 removes the primary attack vector for many legacy exploits and relay-based attacks. By forcing clients and servers to use newer, more secure versions like SMBv3, organizations benefit from improved authentication mechanisms and encryption, which significantly reduces the potential for unauthorized access and lateral movement by malicious actors.
Use cleartext passwords for SMB shares
What is the primary function of SMB (Server Message Block) in a Windows network environment?
To provide a secure method for remote desktop management
To enable file, printer, and resource sharing across a network
SMB serves as the backbone for file and resource sharing in Windows. It enables users and applications to request and receive files and print jobs from remote servers, acting as a critical component of network operations that requires careful security management to prevent data leakage and lateral movement attacks.
To manage directory services and user authentication
To provide encrypted terminal access to server consoles
Which security principle is most directly violated when an organization allows guest access to sensitive SMB file shares?
Defense in depth
Least privilege
Guest access grants everyone on the network the ability to access data, which is the definition of excessive privilege. Following the principle of least privilege requires that every access request be authenticated and authorized, ensuring that only those with a specific need can access the organization's sensitive file shares.
Availability
Non-repudiation
Want more SMB Security practice?
Practice this domainWhich TWO of the following strategies are most effective when using AI tools to assist in the analysis of large-scale, automated malware logs?
Provide the AI with the full, unfiltered enterprise log database without context.
Use the AI to identify outliers in communication patterns compared to historical baselines.
AI excels at identifying statistical deviations in large datasets. By comparing current traffic patterns against established historical baselines, the model can highlight unusual connections, such as unexpected beaconing or data exfiltration attempts. This narrows the scope for the responder, allowing them to focus investigative efforts on high-probability malicious events rather than raw logs.
Task the AI with summarizing log files based on established MITRE ATT&CK techniques.
Mapping log data to the MITRE ATT&CK framework provides actionable intelligence. AI can efficiently categorize log entries by tactic and technique, which accelerates the triage process. This helps responders understand the adversary's lifecycle stage, enabling more accurate prioritization of response actions during the critical containment and eradication phases of the incident.
Rely on the AI to automatically perform incident remediation without verification.
Instruct the AI to ignore all non-standard timestamps to simplify the output.
Refer to the exhibit. An AI-based EDR identifies a suspicious process chain. Based on the provided JSON output, what is the most appropriate next step for an incident handler?
Assume the alert is a false positive due to the common nature of svchost.
Immediately isolate the host from the network based on the 0.98 AI score.
Examine process memory and network artifacts to confirm malicious injection.
Verification is mandatory. By analyzing the memory of the svchost instance and the network connection patterns, the responder confirms whether the process is indeed acting maliciously. This technical validation bridges the gap between an automated alert and actionable intelligence, allowing for a decisive and informed response to the identified threat.
Restart the svchost service to terminate the suspicious connection.
Which of the following is the primary risk associated with using unvetted AI models for malware signature generation?
The model will always generate signatures that are too complex to implement.
The model may produce signatures that trigger on benign system binaries.
AI models trained on insufficient or biased data often fail to distinguish between malicious and legitimate system activity. This leads to the generation of false-positive signatures that flag critical OS files. Deploying such signatures in a production environment causes significant operational disruption, effectively creating a self-inflicted denial-of-service attack for the organization.
The model will consume excessive processing power on the endpoint.
The model will force the malware to evolve into a polymorphic variant.
An analyst is training a machine learning model to classify malware families. Which data preparation technique is most critical to prevent bias in the classification results?
Including only the most recent malware samples in the dataset.
Manually labeling only a small subset of the total available samples.
Ensuring a balanced distribution of samples across all malware classes.
Balanced data prevents the model from favoring majority classes. By providing an equal representation of various malware families, the algorithm learns the distinct features of each, leading to higher accuracy during inference. This balanced approach is critical for maintaining high detection rates across diverse threat vectors during active incident investigations.
Removing all features that contain obfuscated code or strings.
An analyst notices that an AI-powered detection tool is flagging legitimate administrative PowerShell scripts as malicious. Which approach should the analyst take to improve model precision?
Disable the detection rule entirely until the AI update is released.
Update the training set to include these scripts as 'benign' examples.
Adding false positives to the training set allows the model to learn the boundary between legitimate admin activity and malicious PowerShell usage. This process of continuous learning improves model accuracy over time, significantly reducing the burden on the SOC by filtering out expected, non-malicious behavior from the daily alert queue.
Increase the sensitivity threshold of the AI model to ignore all PowerShell activity.
Replace the AI model with a static signature-based detection system.
When investigating an AI-generated spear-phishing campaign, what is the most effective indicator to look for that suggests the content was created by a Large Language Model (LLM)?
Presence of multiple spelling and grammatical errors.
Consistent, overly formal tone that lacks specific organizational context.
AI models tend to default to a polite, formal, and generic tone when instructed to write persuasive emails. They often lack the 'tribal knowledge' or specific cultural context of the target organization. This generic nature is a strong indicator of AI generation, as human-written phishing often contains specific internal references or unique colloquialisms.
Inclusion of malicious code within the email header metadata.
The email is sent from a known, compromised account.
Want more Malware and AI-Assisted Investigations practice?
Practice this domainAn incident responder notices that a legacy web application stores user credentials using MD5 hashing without salt. Which vulnerability is the primary risk during a credential database compromise?
Buffer overflow in the authentication module
SQL injection via the login form
Precomputed rainbow table attacks
Rainbow tables rely on precomputed hash values for common passwords. Because MD5 is fast and unsalted, attackers can pre-calculate hashes for millions of strings. When a database is stolen, they compare the stolen hashes against the table, revealing plaintext passwords in seconds rather than days of brute forcing.
Man-in-the-middle interception
Which TWO of the following are considered best practices for password hashing to mitigate offline cracking?
Use a unique, random salt for every user
A unique salt ensures that two users with the same password have different hash outputs. This effectively neutralizes precomputed rainbow table attacks because the attacker would need to generate a new table for every unique salt value, which is computationally impossible for large user databases.
Use a global static pepper appended to all hashes
Employ a high-cost key derivation function
Functions like Argon2, bcrypt, or scrypt are designed to be computationally expensive. By adjusting the work factor, organizations can increase the time required to hash a password, significantly slowing down offline cracking attempts. This forces attackers to invest massive hardware resources for relatively little gain in speed.
Truncate passwords to 8 characters to save space
Store hashes in plain text for performance
What is the primary function of a salt in password storage?
To increase the length of the password string
To prevent precomputed rainbow table attacks
Salts prevent rainbow tables by ensuring that the hash for a password like 'password123' is unique for every user. Because the attacker cannot precalculate the hashes for all possible salts, they cannot use a standard table to crack the stolen database quickly, forcing a much slower brute-force approach.
To encrypt the password in the database
To hide the algorithm type from attackers
Which of the following describes a 'credential stuffing' attack?
Exploiting a buffer overflow to bypass login
Using valid credentials from one site to access another
This is the definition of credential stuffing. Because users often reuse passwords, attackers leverage large databases of leaked username/password pairs to gain unauthorized access to accounts on other services, assuming that the credentials will be valid in multiple locations due to human password reuse habits.
Brute-forcing a password using a dictionary file
Intercepting credentials via a phishing email
Why are GPUs highly effective at cracking password hashes compared to traditional CPUs?
GPUs have higher clock speeds than CPUs
GPUs perform massively parallel operations
The architecture of a GPU allows it to perform thousands of concurrent calculations. Because each hash attempt is independent of the others, this parallel architecture allows for immense throughput. This turns what would take years on a CPU into a task that takes hours or days on a GPU.
GPUs access system RAM faster than CPUs
GPUs use a different instruction set than CPUs
Why does the use of pepper provide additional security for password hashes, and where should it ideally be stored?
Stored in the same database table; prevents rainbow tables
Stored in a separate environment variable; adds an extra layer
Storing the pepper in a secure, separate location (like an environment variable or HSM) ensures that a database leak alone does not expose the passwords. The attacker would need both the database and access to the server's configuration/environment to have any hope of cracking the hashes.
Stored in the application code; ensures performance
Stored in the user session; ensures unique hashes
Want more Understanding Passwords practice?
Practice this domainAn adversary uses PowerShell to establish a reverse shell. The command includes the '-EncodedCommand' flag with a long Base64 string. What is the most effective way to detect this activity without relying on static command signatures?
Block all outbound connections originating from PowerShell processes.
Enable PowerShell Script Block Logging to capture de-obfuscated code.
Script Block Logging captures the final, de-obfuscated script content that is actually executed by the PowerShell engine. This bypasses the Base64 encoding completely, giving analysts visibility into the raw commands. This is the industry-standard method for detecting and investigating malicious PowerShell usage in enterprise environments today.
Monitor for any usage of the 'powershell.exe' process in logs.
Perform string analysis on all files in the system directories.
Refer to the exhibit. An analyst observes this command output on a compromised server. What is the most likely intent of the attacker?
Listing available files for exfiltration.
Preparing for ransomware deployment by removing backups.
The deletion of volume shadow copies is a standard step for ransomware operators to prevent victims from restoring files without paying the ransom. By identifying this command early, an analyst can potentially stop the encryption process before the damage is done, demonstrating the effectiveness of proactive log monitoring.
Escalating privileges to the SYSTEM account.
Cleaning up evidence of previous tool execution.
An analyst detects an outbound connection using a non-standard port that exhibits high-frequency 'jitter'. Which technique best characterizes the nature of this communication?
Data exfiltration using high-speed burst transfers.
Command and control beaconing with evasion techniques.
Jitter is a common C2 evasion technique used to defeat detection systems that look for perfectly periodic connections. By adding randomness to the delay between beacons, the adversary masks the automated nature of the communication. This indicates a high level of sophistication and necessitates heuristic-based detection methodologies.
Standard web browsing activity during lunch hours.
Network congestion caused by heavy application traffic.
When investigating a suspected malicious process in memory, why is it critical to analyze the 'Parent Process ID' (PPID) in conjunction with the process's execution path?
To identify which user account initiated the malicious activity.
To detect anomalies in process lineage and execution context.
Analyzing the parent process is essential to determine if a process was spawned by an expected entity. Anomalous process lineages, such as a browser spawning a command shell, are strong indicators of exploitation. This context helps differentiate between normal system operations and malicious activity, enabling effective incident detection and root-cause analysis.
To determine the file creation date on the disk.
To ensure the process is running with administrative privileges.
An analyst is reviewing logs and finds multiple failed logins followed by a single successful login from a different IP address, which then executes 'whoami' and 'net user'. What is the most likely scenario?
A user struggling to remember their password.
Credential stuffing followed by automated reconnaissance.
The combination of multiple failed logins and immediate post-exploitation commands is a high-confidence indicator of account compromise. The attacker is mapping the environment to plan further movement. Detecting this progression allows the responder to isolate the compromised account before the adversary can escalate privileges or deploy additional malicious tools.
A network administrator performing routine maintenance.
An automated script updating software versions.
Which THREE actions are effective at identifying hidden 'living-off-the-land' (LotL) binary usage in a compromised system?
Reviewing command-line argument logs for suspicious flags.
LotL binaries often require specific, unusual flags to perform malicious tasks like downloading content or executing remote code. Logging and analyzing these command-line arguments is the most effective way to detect misuse of trusted binaries, as the tool itself is legitimate but the parameters reveal the attacker's intent.
Monitoring for unexpected network connections from system tools.
Standard administrative tools, such as certutil or bitsadmin, should not initiate external network connections for unknown purposes. Monitoring for such connections is a high-fidelity indicator of LotL abuse. Attackers frequently use these tools to download second-stage payloads or establish C2, making network-aware endpoint monitoring essential for detection.
Scanning the disk for all instances of binary files.
Auditing process lineage to identify suspicious parent-child relations.
Legitimate tools are typically spawned by administrative processes like 'services.exe' or the user's shell. If a web server process spawns 'powershell.exe' or 'certutil.exe', it is a strong indicator of an exploit chain. Auditing these relationships is crucial for detecting LotL attacks where the attacker leverages trusted binaries improperly.
Restricting all user permissions to local system accounts.
Want more Detecting Exploitation and Covert Communication Tools practice?
Practice this domainAn attacker uses living-off-the-land binaries (LotLbins) to execute a malicious PowerShell script. Which detection strategy best identifies this activity while minimizing false positives from administrative scripts?
Block all PowerShell execution via Group Policy Objects.
Flag any process execution involving native Windows binaries.
Monitor process lineage for common utilities launching suspicious child processes.
Analyzing parent-child relationships allows security teams to identify anomalies such as a web server process spawning cmd.exe or a utility like certutil.exe initiating an outbound connection. This behavioral pattern is a hallmark of post-exploitation activity, providing high-fidelity signals that distinguish administrative use cases from malicious abuse of trusted binaries.
Implement static file hash signatures for all known LotLbins.
An adversary is using reflective DLL injection to evade detection. Which TWO indicators would most reliably suggest this activity is occurring?
Presence of a new file with an unusual extension in the system directory.
Memory regions with Read/Write/Execute (RWX) permissions within a process.
Memory regions marked as RWX are highly unusual in normal applications. Attackers use these permissions to write their malicious code into memory and then execute it immediately. Detecting these memory segments is a primary indicator of injected code or shellcode running within the address space of a legitimate process.
Increased usage of CPU by background system services.
Loaded modules lacking a corresponding file path on the disk.
Legitimate DLLs are usually backed by a physical file on the disk. When a DLL is loaded reflectively, it exists only in memory, and the operating system's module list will often show a loaded image with no associated file path. Identifying these orphaned modules is a definitive sign of memory-resident code.
An increase in the number of network connections to unknown IPs.
Which technique describes an attacker using a legitimate process to hide malicious code, commonly used to bypass security products that monitor only the primary process?
DLL Side-Loading
Process Hollowing
Process hollowing involves creating a legitimate process in a suspended state, unmapping its original memory, and replacing it with malicious code. This allows the attacker to execute their payload under the guise of a trusted, signed application, successfully bypassing many security controls that monitor for process startup patterns.
AppInit_DLLs
Token Impersonation
An incident responder notices that a local user account is performing Kerberoasting. Which event log ID should the responder examine to verify this activity?
Event ID 4624
Event ID 4769
Event ID 4769 is generated when a service ticket is requested in an Active Directory environment. By filtering for Kerberos encryption types, specifically weak ones like RC4 (encryption type 0x17), security analysts can identify potential Kerberoasting attempts where an attacker requests tickets to extract credentials for offline cracking.
Event ID 4720
Event ID 4688
What is the primary purpose of 'Time Stomping' during a post-exploitation phase?
To crash the file system and hide malicious processes.
To bypass file integrity monitoring (FIM) signatures.
To blend malicious files into the existing file system timeline.
Time stomping is used to manipulate file metadata so that malicious files appear to be legitimate system files created long ago. This makes it significantly harder for human investigators to find files created during the window of compromise when searching for suspicious indicators based on time.
To increase the privilege level of the attacker.
Which behavior is indicative of a 'Golden Ticket' attack occurring in a Windows environment?
The user password is changed without authorization.
Unusually long ticket lifetimes or requests without an initial AS-REQ.
Golden tickets are forged with custom, often extremely long, lifetimes and are injected into the session without the standard Authentication Service Request (AS-REQ) phase. Observing these anomalies in Kerberos traffic is a primary indicator of a compromised domain controller or the use of forged tickets.
An increase in NTLM traffic across the domain.
The creation of a new, highly privileged domain administrator.
Want more Detecting Evasive and Post-Exploitation Techniques practice?
Practice this domainAn incident responder is evaluating a compromised web application server where attackers utilized a custom Large Language Model framework to dynamically generate targeted SQL injection payloads based on real-time database error feedback. Which architectural vulnerability in the LLM integration enabled this adaptive offensive capability?
Failure to enforce strict context-window limits on the primary transformer model
Unrestricted execution loops connecting model output directly to database querying modules
Allowing an LLM agent to directly execute generated queries based on unvalidated error responses creates an autonomous offensive loop. This systemic design flaw enables real-time payload mutation, turning the model into an adaptive exploitation engine capable of bypassing traditional perimeter defenses.
Implementation of outdated quantization techniques on the local embedding weights
Misconfigured vector database permissions allowing unauthorized embedding vector reads
During a forensic analysis of a compromised developer workstation, an incident handler discovers scripts showing an attacker utilized an LLM to automate reconnaissance tasks. Which TWO capabilities are typically enhanced when integrating LLMs into modern offensive enumeration workflows? (Choose two)
Synthesizing unstructured banner-grabbing outputs into structured asset inventories
Large Language Models excel at parsing messy, inconsistent service banner strings and raw network scan outputs into neatly organized JSON inventories. This capability drastically reduces the manual analysis overhead typically required during the initial reconnaissance and asset discovery phases.
Direct physical manipulation of smart-city IoT gateway switches via radio frequency
Autonomously generating custom multi-threaded port scanner binaries in compiled C
Translating natural language directives into complex, context-specific command pipelines
Attackers leverage LLMs to translate high-level tactical objectives, such as finding specific user files, directly into complex shell command pipelines. This bridges the gap between human intent and intricate syntax requirements, accelerating execution velocity on target hosts.
Bypassing hardware-enforced memory encryption mechanisms on remote hypervisors
An incident responder is using an LLM to automate the parsing of obfuscated PowerShell scripts found during a breach. What is the primary operational risk when feeding these scripts into a cloud-based LLM API?
The LLM will automatically execute the PowerShell commands in the cloud environment.
The LLM will refuse to analyze the script because it contains malicious syntax.
The input data may be retained and used for future model training, potentially leaking incident indicators.
Cloud providers often ingest user input for continuous model improvement. If sensitive environment variables, internal server names, or specific attack indicators are present in the script, they could be reflected in future model outputs, resulting in a significant data leakage incident that compromises the organization's security posture.
The LLM will inject backdoors into the code during the deobfuscation process.
Which technique is most effective for preventing prompt injection when integrating an LLM into an automated security orchestration tool?
Retraining the model on internal security documentation.
Using clear delimiters to differentiate between system instructions and user-supplied data.
Delimiters provide a structural boundary that helps the model categorize input. When system instructions are clearly defined and set apart from user input, the model is significantly less likely to prioritize adversarial input that mimics system-level commands, thereby mitigating the primary vector for successful prompt injection attacks during execution.
Encrypting the prompt before sending it to the LLM API.
Limiting the LLM context window to 1024 tokens.
Which of the following describes an 'LLM Hallucination' in the context of analyzing an unknown binary?
The model successfully deobfuscates the binary and identifies a buffer overflow.
The model generates a convincing but false explanation of a function's purpose.
Hallucinations often involve the model providing a logical, confident explanation for code that it does not actually understand. In binary analysis, the model may confidently describe a function as a cryptographic routine when it is actually just a simple data copy, leading the analyst to incorrect conclusions.
The model refuses to analyze the binary due to safety policy violations.
The model correctly identifies the compiler used to build the binary.
An analyst uses an LLM to generate a C++ exploit. The model provides code that uses an deprecated memory copy function. What is the most appropriate action for the analyst to take?
Execute the code immediately in the production environment to verify functionality.
Modify the code to use modern alternatives and perform rigorous security testing.
Manual review is a critical step in the AI development pipeline. Replacing deprecated functions with modern, secure alternatives and testing the payload in a controlled environment ensures the code is both functional and safe to use, mitigating the risks associated with the model's tendency to suggest outdated coding patterns.
Re-run the prompt with a higher temperature to get a different code version.
Accept the code as is, as the LLM has already accounted for the system requirements.
Want more Integrating LLMs with Offensive Operations practice?
Practice this domainAn incident responder notices a spike in outbound traffic on port 443 originating from a server that normally only communicates with a local database. Which tool is most effective for identifying the specific process responsible for this anomalous network activity?
tcpdump -i eth0
netstat -ano
The -ano flags in netstat display all active connections, include numeric addresses, and show the process ID owning each connection. This direct mapping allows the responder to identify the exact binary or service responsible for the outbound port 443 traffic, facilitating immediate containment actions against the process.
nmap -sV target
ifconfig -a
An analyst is investigating potential data exfiltration via DNS tunneling. Which TWO of the following indicators would most strongly suggest this activity is occurring?
A sudden increase in DNS TXT record requests
DNS TXT records are often used in tunneling because they can store arbitrary data strings. A significant spike in these requests, especially to an unknown or suspicious domain, is a strong indicator that an attacker is using the DNS protocol as a covert transport mechanism.
High volumes of HTTP GET requests to internal IPs
Unusually long, randomized subdomain strings
In DNS tunneling, the data being exfiltrated is encoded into the subdomain portion of the query. These subdomains often appear as long, high-entropy, randomized strings. Detecting these strings in logs is a hallmark technique for identifying data exfiltration hidden within legitimate DNS traffic.
Frequent ICMP echo requests from the perimeter
TCP SYN floods targeting the local gateway
Which of the following best describes the purpose of 'flow data' (like NetFlow) during an incident investigation?
To capture the full payload content of every packet.
To provide a record of who accessed which specific file.
To analyze the volume, source, and destination of network traffic.
Flow data is specifically designed to provide summary information about network traffic. This includes the source IP, destination IP, ports, protocol, and the volume of data transferred, which is essential for identifying anomalous communication patterns during a post-incident forensic investigation.
To perform real-time decryption of SSL/TLS traffic.
You are analyzing a PCAP and notice a large number of packets with the 'RST' flag set. What is the most likely cause for this behavior in an incident context?
Successful data transfer.
Port scanning activity.
Port scanners often trigger RST responses when they attempt to connect to closed ports. When a scanner sends a SYN packet to a closed port, the target host responds with an RST/ACK to signal the connection is refused, creating a noticeable pattern of RST packets in traffic.
Normal encrypted session renegotiation.
DNS zone transfer.
An analyst discovers a suspicious file named 'svchost.exe' running from a user's 'AppData' directory. Why is this highly suspicious?
It is always a virus.
Svchost must always run as SYSTEM.
Legitimate svchost.exe resides in System32.
The actual Windows svchost.exe binary is located in C:\Windows\System32. When an executable with the same name is found in a user's AppData directory, it is almost certainly a malicious attempt to hide in plain sight while maintaining persistence, which is a classic indicator of compromise.
Svchost cannot be executed by users.
Which of the following is a primary benefit of using a centralized log management (CLM) solution during an incident?
It automatically blocks all malicious traffic.
It provides a unified view for log correlation.
The main benefit of a CLM solution is its ability to aggregate logs from multiple devices into one searchable interface. This enables analysts to correlate activities, such as matching a network login on a server with an unusual process start on an endpoint, which is essential for investigation.
It encrypts all data on the network.
It prevents unauthorized local access.
Want more Network and Log Investigations practice?
Practice this domainAn attacker manipulates a URL parameter `?file=invoice_123.pdf` to `?file=../../etc/passwd` on a web server. The application successfully returns the sensitive system file content. Which vulnerability is being exploited?
Cross-Site Request Forgery
Path Traversal
Path Traversal exploits insufficient security validation of user-supplied input files. By injecting directory traversal sequences like double-dot-slash, attackers manipulate the server's file system path resolution. This allows unauthorized access to arbitrary files on the underlying operating system that should remain inaccessible to the web application process.
SQL Injection
Server-Side Request Forgery
Which TWO of the following practices are the most effective at mitigating Insecure Direct Object Reference (IDOR) vulnerabilities?
Implementing server-side authorization checks for every object access
Verifying that the current authenticated user has explicit permission to access the requested object is the definitive mitigation for IDOR. Without this server-side validation, users can simply modify request parameters to view data belonging to other users, rendering any other security control ineffective against logical authorization bypasses.
Using random, non-sequential identifiers for objects
Transitioning from sequential integers to globally unique identifiers (UUIDs) makes it computationally infeasible for attackers to enumerate or guess valid object references. While this does not replace authorization, it significantly reduces the attack surface by preventing trivial discovery of resources through automated scanning or manual parameter incrementing.
Increasing the length of session tokens
Employing a Web Application Firewall (WAF)
Moving all sensitive data to a cloud storage bucket
When auditing an application for Insecure Direct Object References, why is it recommended to perform tests using two distinct user accounts?
To verify if the server is load balanced
To ensure that session cookies are not reused
To confirm that the application does not validate object ownership
By logging in as User A and attempting to access an object owned by User B, the auditor confirms if the application performs authorization checks. If the request succeeds, it proves the system only validates the session, not the ownership of the referenced object, confirming the IDOR flaw.
To test the strength of the password hashing
An application uses a Base64 encoded string as a parameter for object references. An attacker decodes the string, modifies the ID, re-encodes it, and successfully accesses unauthorized data. Why did the security control fail?
Base64 encoding is inherently reversible
Base64 is a reversible encoding scheme, not an encryption method. Attackers can easily decode and modify the payload before re-encoding it. The security failure stems from the reliance on this 'obfuscation' instead of implementing robust server-side authorization checks to verify if the user is permitted to access the modified ID.
The server failed to enforce HTTPS
The session token was not included in the payload
The application used an insecure hashing algorithm
Which of the following is the most secure method for handling file references in a web application to prevent path traversal?
Sanitizing input by removing '..' sequences
Using indirect references via a database lookup
Using indirect references decouples the user-supplied input from the actual file system path. By mapping a simple identifier to a specific file location on the back-end, the application ensures that users cannot influence the path resolution process. This is the recommended secure design pattern to prevent directory traversal and related attacks.
Encrypting the file path in the URL
Allowing only alphanumeric characters in the filename
Which of the following is the most critical step to perform after detecting a successful IDOR exploit?
Restart the web server service
Audit access logs to assess the scope of data exposure
IDOR vulnerabilities frequently allow mass data exfiltration. After detection, the priority is identifying how much data was accessed by the attacker. Analyzing access logs helps quantify the breach, allowing for an accurate impact assessment and compliance reporting, which are required when handling incidents that expose personal or sensitive organizational data.
Block the attacker's IP address on the firewall
Rotate all user passwords in the system
Want more Exploiting Insecure Web App References practice?
Practice this domainAn incident responder investigates a RESTful API where users can access sensitive records simply by incrementing an integer ID in the endpoint URL, such as changing /api/v1/users/104/profile to /api/v1/users/105/profile without providing additional authorization checks. Which vulnerability class does this scenario represent?
Cross-Site Request Forgery
Broken Object Level Authorization
APIs frequently expose endpoints that handle object identifiers, creating a wide attack surface for object-level access control flaws. Without proper authorization validation verifying whether the logged-in user owns the requested object ID, attackers easily iterate through identifiers to read or modify private data records.
Server-Side Request Forgery
Mass Assignment
During a web application incident investigation, the SOC analyst discovers that an attacker sent a modified JSON payload containing an unexpected administrative attribute "is_admin": true during user registration, which successfully elevated the user's privileges. What vulnerability enabled this exploitation?
Broken User Authentication
Server-Side Request Forgery
Mass Assignment
Mass assignment arises when automated object mapping features bind HTTP request parameters directly to internal data structure properties. Attackers exploit this by appending sensitive fields like role or status flags to registration or profile update payloads to gain unauthorized administrative privileges.
Cross-Site Scripting
An attacker discovers an API endpoint /api/v1/user/details?id=123 that returns JSON data. They modify the parameter to /api/v1/user/details?id=124. This vulnerability indicates a failure in which security control?
Broken Authentication
Insecure Direct Object Reference
IDOR occurs when an application provides direct access to objects based on user-supplied input. By manipulating the ID parameter, the attacker accesses unauthorized data records. APIs are particularly susceptible to this when they rely on sequential IDs for object retrieval without verifying user permissions.
Cross-Site Scripting
Insufficient Logging and Monitoring
Which TWO methods are effective for mitigating Mass Assignment vulnerabilities in RESTful APIs?
Implement strict input allow-lists for model binding
Defining an explicit allow-list of fields that the API is permitted to bind ensures that unexpected or sensitive fields provided by the client are ignored. This technique creates a secure boundary between external input and internal object properties, effectively neutralizing Mass Assignment risks.
Use Data Transfer Objects (DTOs) for input mapping
DTOs provide an intermediary layer that separates the API's external request schema from the internal database model. By explicitly mapping only safe fields from the DTO to the model, developers prevent unauthorized property modification, maintaining strict control over the data that reaches the backend storage.
Always sanitize input for SQL injection patterns
Increase the complexity of the API authentication token
Disable all write operations on public API endpoints
An API uses OAuth 2.0. An attacker sends a request with a modified 'redirect_uri' parameter to an authorization endpoint. If successful, this could lead to which type of vulnerability?
Denial of Service
Cross-Site Request Forgery
Authorization Code Interception
By modifying the redirect_uri to an attacker-controlled endpoint, the authorization server redirects the user's browser with the authorization code sent to the attacker. The attacker then exchanges this code for a valid access token, bypassing standard authentication flows and gaining full access to the victim's account.
Server-Side Request Forgery
Which THREE items are essential components of an API security documentation strategy for incident responders?
Up-to-date OpenAPI/Swagger specifications
OpenAPI documents provide a ground truth of the API's intended design, including expected input formats, authentication methods, and endpoint definitions. Responders use this to detect anomalies by comparing actual request structures against the documented schema to identify malicious variations or unexpected inputs.
Complete inventory of all exposed API endpoints
Shadow APIs and undocumented endpoints are prime targets for attackers. A complete inventory ensures that security teams can monitor and audit every entry point. Without knowing what is exposed, responders cannot effectively investigate unauthorized access or detect activity originating from forgotten or unmonitored legacy API endpoints.
Detailed API rate-limiting and throttling policies
Documented rate-limiting policies help distinguish between aggressive automated scanning and legitimate user traffic. Knowing the thresholds allows responders to determine if an attacker is attempting to bypass security or exhaust resources. This is crucial for configuring detection logic in WAFs or API gateways during incidents.
Hardcoded database credentials for internal services
Customer personal identifiable information (PII) logs
Want more Web App API Attacks practice?
Practice this domainAn incident responder investigates a web application running a legacy PHP backend. Users report that searching for specific product SKUs causes the application to dump database table structures directly onto the results page. Which underlying vulnerability class is most likely responsible for this behavior?
Cross-Site Scripting via injected JavaScript payloads in the SKU search field
Error-based SQL injection via unescaped search input processed directly by the database engine
Unsanitized user inputs concatenated directly into SQL query strings allow attackers to manipulate execution flow and trigger database errors. Verbose database exceptions outputted to the user interface reveal structural details, making error-based SQL injection the primary suspect for this specific application behavior.
Remote Code Execution via insecure deserialization of serialized PHP objects
XML External Entity injection via malformed search queries processed by an XML parser
An incident handler is analyzing an incident where a web application was compromised via SQL injection. The backend database uses a modern relational database management system. Which TWO of the following remediation strategies are considered primary defenses against SQL injection attacks? (Choose TWO)
Implementing parameterized queries or prepared statements for all database interactions
Parameterised queries and prepared statements separate SQL code from user-supplied data, so input is bound as values rather than concatenated into statements. The database never interprets injected text as executable SQL, satisfying the primary defence requirement against SQL injection.
Enabling client-side JavaScript validation to strip out single quotes and semicolons
Applying robust input validation and whitelisting against expected parameter formats
Input validation with whitelisting rejects malformed or unexpected parameter values before they reach the database, preventing attacker-supplied SQL syntax from being interpreted. It satisfies the primary defence requirement by constraining input to expected formats at the application boundary.
Relying exclusively on Web Application Firewall signature blocking rules
Encoding all database query outputs using HTML entity encoding before rendering
An organization discovers that an attacker executed operating system commands via a vulnerable web application endpoint. The application takes user input, constructs an XML payload, and passes it to an underlying XML parser without disabling external entity resolution. Which type of vulnerability enabled this command execution?
Server-Side Template Injection via malicious expressions evaluated by template engines
XML External Entity injection exploiting insecure XML parser configurations
Failing to disable Document Type Definitions and external entity resolution in XML parsers allows attackers to read local files or trigger out-of-band requests. When combined with specific PHP wrappers, XXE can escalate into direct operating system command execution.
Cross-Site Scripting via injected script tags within CDATA sections
LDAP injection through improper attribute filtering in directory search queries
During an incident response engagement involving a web application, an analyst uncovers evidence of Command Injection. Which TWO indicators or technical conditions strongly support this specific finding? (Choose TWO)
Presence of shell metacharacters like pipes, ampersands, or semicolons within HTTP parameter values
Shell metacharacters allow attackers to chain multiple commands together in a single execution stream. Observing characters like pipes or semicolons in web server access logs strongly indicates an attempt to break out of intended application logic into the shell.
Database error logs displaying syntax violations from unmatched table column counts
Web server worker processes spawning unexpected child processes like cmd.exe or /bin/sh
When command injection succeeds, the web service process invokes a system shell interpreter to execute the payload. Detecting unexpected shell child processes spawned by web server workers is a definitive forensic artifact of successful command execution.
Application configuration files storing plaintext database connection passwords
Client-side DOM manipulation errors logged within browser developer console windows
An incident investigator reviews application logs showing that an attacker manipulated session tokens by altering underlying JSON Web Tokens without knowing the signing secret. The attacker successfully forged valid-looking administrative sessions. Which server-side vulnerability enabled this behavior?
Server-Side Request Forgery via unvalidated webhook URLs
Improper JWT algorithm validation permitting the 'none' signing algorithm
Failing to explicitly whitelist permitted cryptographic algorithms allows clients to specify 'none' in the JWT header. The verification library then bypasses signature checking, treating the unsigned payload as authentic and allowing total session integrity compromise.
SQL injection within the session lookup table query
Cross-Site Scripting enabling session identifier theft from local storage
Which TWO of the following techniques are most effective for preventing Cross-Site Scripting (XSS) in a web application?
Using contextual output encoding.
Contextual output encoding transforms sensitive characters into their safe HTML entity equivalents before rendering data in the browser. By applying specific encoding based on where the data is placed—HTML body, attribute, or JavaScript—the application ensures the browser treats data as content rather than executable script code.
Implementing a strict Content Security Policy (CSP).
A strict CSP allows developers to define which sources of content are trusted. By restricting script execution to specific domains or nonces, CSP significantly mitigates XSS impact even if an attacker successfully injects a payload. This provides a robust defense-in-depth layer against unauthorized code execution within the browser.
Enforcing HTTPS for all application traffic.
Disabling JavaScript in the web browser.
Using basic regex to filter out script tags.
Want more Web App Injection Attacks practice?
Practice this domainWhich TWO steps are critical during the 'Preparation' phase of the incident response lifecycle to ensure effective forensic investigation during a future security breach?
Establishing a centralized logging architecture with immutable storage.
Centralized logs are essential because they prevent attackers from tampering with local event logs after gaining administrative access. By ensuring storage is immutable, the organization guarantees that forensic investigators have an untampered historical record of attacker activity, which is crucial for building a reliable timeline of the intrusion.
Drafting an incident communication plan for notifying public regulatory bodies.
Defining forensic acquisition procedures and chain of custody documentation.
Standardized procedures for acquiring data ensure that the evidence remains legally defensible and technically accurate. Without these protocols in place, responders might inadvertently corrupt or mismanage evidence, rendering it useless for criminal prosecution or internal disciplinary actions against an insider threat actor during the subsequent investigation phase.
Conducting a comprehensive risk assessment of all internal business applications.
Purchasing cybersecurity insurance to cover potential ransomware payout costs.
Refer to the exhibit. An analyst identifies these entries on a critical server. What should the analyst conclude regarding the process associated with PID 4?
The server is likely compromised by a kernel-mode rootkit acting as a listener.
The process is a legitimate Windows kernel operation for SMB file sharing.
PID 4 is the System process, which handles network traffic for the Server service, including SMB (TCP 445). This traffic is typical for a server responding to legitimate client requests. An analyst should differentiate between standard operating system network behavior and suspicious outbound connections to unauthorized external IP addresses.
A remote adversary is using the SMB protocol to exfiltrate data from the system.
The system is currently scanning the network for vulnerabilities using SMB exploits.
During a digital investigation, an incident responder is asked to preserve memory from a compromised Linux server. Which tool is most appropriate for a forensically sound memory acquisition?
The 'dd' command to copy /dev/mem directly to a remote storage server.
LiME (Linux Memory Extractor) to generate an image file for offline analysis.
LiME is the industry-standard tool for Linux memory acquisition because it is specifically designed to handle the complexities of kernel memory. It minimizes system impact and can be used to stream the memory image over the network, ensuring that the evidence is captured with high fidelity and integrity.
The 'cat' command to pipe the contents of /proc/kcore into a file.
Installing a commercial agent to automate the imaging process via a GUI.
An organization detects a web-based attack and wants to perform a thorough investigation. Which THREE artifacts should the team collect to analyze the adversary's entry point and activity?
HTTP access and error logs from the web server.
Web server logs are the primary source for identifying the attacker's source IP, the requests made, and the server's response codes. Error logs often reveal failed exploitation attempts or crashes caused by malicious payloads, providing critical context for how the attacker attempted to compromise the application layer.
System event logs for all workstations in the local network.
Application-level logs and database transaction logs.
Application logs often contain details about user sessions, authentication attempts, and input validation failures that standard web logs miss. Database logs are critical for identifying SQL injection attacks or unauthorized data modification, which are common objectives for adversaries targeting web applications and their underlying data stores.
Email gateway logs showing internal-to-external communication patterns.
Network perimeter firewall and WAF traffic logs.
Firewall and WAF logs provide the network context for the attack, including the inbound connections and any rules triggered by the malicious traffic. These logs help confirm the external source and show if the organization’s defensive controls blocked any stages of the attack, which informs the scope of the investigation.
Which phase of the incident response process is most likely to involve the creation of a 'lessons learned' report to improve future security posture?
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
The Post-Incident Activity phase is designed specifically for conducting a formal review of the incident response process. By documenting successes and failures, the organization can implement systemic changes to security controls, training, and response procedures, effectively closing the loop on the incident and enhancing future resilience.
Preparation
Refer to the exhibit. An analyst deploys this policy to detect threats. Why is the 'parent_process' condition specifically targeting 'w3wp.exe'?
To detect unauthorized software installations performed by administrative users.
To identify potential web shell execution or exploit payloads triggered via IIS.
IIS worker processes (w3wp.exe) should rarely spawn PowerShell. When they do, it is a high-confidence indicator of a web application compromise, such as a web shell executing commands. This detection is tailored to catch the specific behavior of attackers attempting to pivot from a web exploit to system-level execution.
To prevent the web server from being used as a staging ground for brute force.
To ensure that all PowerShell scripts are signed and authorized by the organization.
Want more Incident Response and Cyber Investigation practice?
Practice this domainRefer to the exhibit. Given the hashcat output provided, which type of hash is currently being targeted by the attacker, and what is the primary risk associated with this specific attack mode?
SHA-256; risk of collision attacks
NTLM; risk of credential theft and lateral movement
Hashcat mode 1000 is standard for NTLM. NTLM is the legacy authentication protocol in Windows, and obtaining the plaintext password or the hash allows an attacker to impersonate the user, move laterally through the network, or escalate privileges within an Active Directory forest.
bcrypt; risk of slow brute-force degradation
Kerberos TGT; risk of Golden Ticket generation
Which of the following describes a 'Password Spraying' attack, and why is it preferred by attackers over traditional brute-force methods against a target domain?
Testing thousands of passwords against a single high-privileged account
Using one common password against many different accounts
Password spraying is characterized by the 'low and slow' approach of testing a single password against many accounts. This minimizes failed attempts per account, ensuring that individual user accounts remain active and that the attacker does not trigger account lockout mechanisms during the process.
Capturing hashes via packet sniffing and offline cracking
Injecting malicious code into the authentication form
Which of the following best describes the risk of using 'credential stuffing' against a web application, and how does it differ from a standard dictionary attack?
Dictionary attacks use compromised lists; stuffing uses random passwords
Stuffing tests leaked credentials; dictionary attacks guess passwords
Credential stuffing exploits the human tendency to reuse passwords by automating logins with verified pairs from other breaches. Dictionary attacks are purely probabilistic attempts to guess a password for a single target, making them fundamentally different in execution and success rates.
Dictionary attacks are faster than credential stuffing
Stuffing targets the database; dictionary attacks target the login
When analyzing a compromised system, you find evidence of 'Kerberoasting'. What is the primary objective of this attack, and what specific artifact is the attacker attempting to acquire?
Acquiring the TGT; goal is to forge Golden Tickets
Acquiring the TGS; goal is to crack service account passwords
Kerberoasting involves requesting TGS tickets for SPN-enabled accounts. These tickets are encrypted with the account's password hash. Offline cracking of these tickets reveals the plaintext password, allowing the attacker to escalate privileges if the service account has excessive permissions on the network.
Acquiring the NTLM hash; goal is Pass-the-Hash
Acquiring the PAC; goal is privilege escalation
Refer to the exhibit. Given the provided log entry, which attack is likely occurring, and what does the sub-status code indicate?
Pass-the-Hash; 0xC000006A means the hash is expired
Brute-force/Dictionary attack; 0xC000006A means bad password
Repeated failed logins for an account, especially an administrator account, using NTLM indicate a brute-force or dictionary attack. The sub-status code 0xC000006A is the standard Windows error for an incorrect password provided during the authentication process.
Account lockout; 0xC000006A means account is disabled
Kerberoasting; 0xC000006A means SPN not found
Which of the following best explains why 'Rainbow Tables' are less effective against modern systems that implement salted hashes?
Salting increases the length of the hash, causing buffer overflows
Salts make the total hash space too large to compute
Salts negate the precomputed nature of rainbow tables
Rainbow tables rely on the fact that a specific password always results in the same hash. By appending a salt, the hash calculation changes for each user. An attacker would have to compute a unique table for every single salt, destroying the efficiency of precomputation.
Salts slow down the hashing algorithm significantly
Want more Attacking Passwords practice?
Practice this domainWhich Nmap flag is essential when you need to perform OS fingerprinting to determine the target operating system version during an incident response assessment?
-sV
-A
-O
This flag specifically triggers the OS detection engine within Nmap. It probes the target with various TCP and ICMP packets and compares the responses to a database of known fingerprints. It is the focused command for identifying the target's operating system without the overhead of additional service or script scans.
-sS
A responder is performing a vulnerability scan on a segment containing industrial control systems. Which Nmap timing template should be used to avoid disrupting sensitive, potentially fragile hardware?
T0
T0 is the most cautious timing template, sending packets with a very long delay between them. This approach is ideal for critical or fragile environments where even minor network overhead could cause a system failure, ensuring that the scanning process does not disrupt the availability of time-sensitive and mission-critical hardware systems.
T3
T4
T5
Which tool is best suited for identifying potentially misconfigured SMB services that could be leveraged for lateral movement within a compromised Windows environment?
Wireshark
Nmap with NSE scripts
Nmap is a versatile scanner that, when combined with NSE scripts, can detect specific SMB-related vulnerabilities and configurations. This allows the responder to map the network and verify the security posture of Windows-based machines, identifying potential weak points that could be exploited to gain unauthorized access or move laterally across the network.
Netcat
Tcpdump
Why is it important to randomize the target IP addresses when performing a large-scale network scan?
To reduce the scan duration by optimizing packet routing.
To bypass the target operating system's rate limiting.
To avoid triggering threshold-based IDS alerts on specific subnets.
Randomizing target IP addresses spreads the scanning traffic across the entire network, preventing any single subnet or host from seeing a large spike in connection attempts. This significantly lowers the likelihood of triggering signature-based or threshold-based alerts, allowing the responder to complete the discovery process without immediate detection by security systems.
To ensure the scanner utilizes all available network interfaces.
Which Nmap scan type should be used when the goal is to map the topology of a network and identify active hosts without establishing any TCP or UDP connections?
TCP SYN scan (-sS)
TCP Connect scan (-sT)
ICMP Echo Request (-sn)
The -sn flag performs a ping sweep using ICMP echo requests. This is the standard method for host discovery that bypasses the transport layer, effectively mapping active nodes without ever attempting a TCP or UDP connection. It is the most lightweight method for creating a rapid, low-impact inventory of live hosts.
UDP scan (-sU)
A responder needs to map an internal network but cannot use standard tools due to strict endpoint protection. Which technique can be used with native command-line tools to perform a basic port check on a remote host?
Using a PowerShell Test-NetConnection command.
Test-NetConnection is a native Windows cmdlet that functions similarly to a simplified port scanner. It is an ideal, low-profile method for checking connectivity and port status on Windows systems. Because it is a built-in utility, it is less likely to be flagged by behavioral detection systems than external scanning tools.
Running an nmap.exe binary from a USB drive.
Initiating a telnet session to every port.
Pinging the broadcast address of the subnet.
Want more Scanning and Mapping practice?
Practice this domainThe GCIH exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 15 domains: Securing Credentials and Data in Cloud, Endpoint Attack and Pivoting, SMB Security, Malware and AI-Assisted Investigations, Understanding Passwords, Detecting Exploitation and Covert Communication Tools, Detecting Evasive and Post-Exploitation Techniques, Integrating LLMs with Offensive Operations, Network and Log Investigations, Exploiting Insecure Web App References, Web App API Attacks, Web App Injection Attacks, Incident Response and Cyber Investigation, Attacking Passwords, Scanning and Mapping. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official GIAC GCIH exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.