GCFA Enterprise Environment Incident Response Practice Question
An incident responder is reviewing EDR alerts and discovers an 'Account Manipulation' event. What is the most common reason why an attacker would target the 'Domain Admins' group during the post-exploitation phase?
⚠ Common exam trap
Candidates often confuse the goal of 'Domain Admins' targeting with specific technical outcomes like 'credential dumping' or 'data exfiltration', missing that these are simply intermediate methods to achieve the primary goal of total domain control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To gain unrestricted control over the entire domain and its resources.
Targeting the Domain Admins group is the 'holy grail' for an attacker because it provides full control over the entire Active Directory domain. With these privileges, an attacker can disable security controls, create new accounts, exfiltrate sensitive data, and install persistent backdoors across all systems joined to the domain. This level of access effectively grants the attacker the ability to operate undetected and exert complete influence over the organization's enterprise infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To bypass the need for multi-factor authentication on local machines.
Why it's wrong here
MFA is typically enforced at the identity provider level, not by group membership alone. Being a Domain Admin does not automatically disable MFA for all endpoints; rather, it allows the attacker to potentially modify the configuration to weaken or disable MFA for the entire domain, but it's not the direct bypass method.
- ✓
To gain unrestricted control over the entire domain and its resources.
Why this is correct
Domain Admin is the most powerful privilege level in a Windows domain. By successfully compromising this group, an attacker inherits the ability to perform any action on any object within the domain, effectively giving them complete authority to manipulate resources, settings, and user access across the whole enterprise network.
- ✗
To encrypt the Active Directory database for ransomware demands.
Why it's wrong here
While an attacker with Domain Admin access could theoretically delete or corrupt the AD database, their goal is usually to steal data or maintain long-term access rather than just destroying infrastructure. Ransomware typically targets file shares and databases, not the underlying domain controller infrastructure which would impede the decryption process.
- ✗
To hide their tracks by clearing the Windows Event logs globally.
Why it's wrong here
While Domain Admins can clear logs, this is an anti-forensic tactic rather than the end goal. Attackers target the group for the massive access it provides to the network, not primarily for the ability to clear logs, which can often be achieved through other means with less noise or risk.
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.