GCIH Practice Question: Detecting Evasive and Post-Exploitation Techniques
What is the primary indicator of a 'Skeleton Key' attack in an Active Directory environment?
⚠ Common exam trap
Candidates often confuse Skeleton Key with Golden Ticket. They fail to realize Skeleton Key is a memory patch on the DC, not a forged ticket structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Successful authentication using a custom password for multiple users.
A Skeleton Key attack injects a patch into the LSASS process on a domain controller, allowing the attacker to authenticate as any user using a single, 'master' password. This is a devastating post-exploitation technique because it grants the attacker domain-wide access without needing to crack individual user hashes. Detecting this requires monitoring for memory anomalies in LSASS on DCs and auditing for suspicious modifications to critical system processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All user passwords in the domain are suddenly reset.
Why it's wrong here
A Skeleton Key attack does not require resetting user passwords. The goal is to silently bypass the authentication check using the injected master password, so changing passwords would actually alert users and administrators, which defeats the purpose of the stealthy access the attacker has achieved.
- ✗
The domain controller crashes during authentication.
Why it's wrong here
While memory injection carries the risk of instability, a Skeleton Key attack is designed to be stable enough to persist across authentication attempts. Frequent crashes would cause operational disruption and attract the attention of IT staff, which is counter-productive to the attacker's goal of persistent, covert access.
- ✓
Successful authentication using a custom password for multiple users.
Why this is correct
The defining characteristic of a Skeleton Key attack is that the attacker can use a single, hardcoded password to log in as any user on the network. Detecting a sudden spike in diverse user accounts authenticating with the same password is a definitive sign of this attack.
- ✗
Increased replication traffic between domain controllers.
Why it's wrong here
Skeleton Key is a local memory injection attack on a specific domain controller. It does not inherently trigger increased replication traffic. Replication issues are typically related to infrastructure health or synchronization delays, not the application of a patch to the LSASS process for credential bypassing.
About these practice questions
Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.