GIAC GDAT Certification Sample Questions

GDAT Dumps, GDAT PDF, GDAT VCE, GIAC Defending Advanced Threats VCE, GIAC GDAT PDFThe purpose of this Sample Question Set is to provide you with information about the GIAC Defending Advanced Threats (GDAT) exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the GDAT certification test. To get familiar with real exam environment, we suggest you try our Sample GIAC GDAT Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual GIAC Defending Advanced Threats (GDAT) certification exam.

These sample questions are simple and basic questions that represent likeness to the real GIAC Defending Advanced Threats exam questions. To assess your readiness and performance with real-time scenario based questions, we suggest you prepare with our Premium GIAC GDAT Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

GIAC GDAT Sample Questions:

01. On a hardened host, an attacker uses an information leak to defeat address randomization and builds a return-oriented chain so that non-executable memory is not an obstacle. The exploit then corrupts a function pointer to hijack an indirect call and redirect execution.
Which additional mitigation most directly constrains this indirect-call hijack?
a) Data Execution Prevention on data pages
b) A stack canary guarding the saved return address
c) Strong service-account passwords
d) Control Flow Guard, which validates indirect call and jump targets against a set of valid destinations
 
02. Employees are compromised after visiting several unrelated but reputable news sites. Investigation shows the sites themselves were never breached; the malicious content arrived through a third-party advertising slot that redirected a fraction of visitors to an exploit.
Which delivery technique does this describe?
a) Malvertising
b) A watering-hole attack, where the visited site itself is compromised
c) Spear-phishing via a link emailed to each employee
d) A drive-by download hosted directly on each news site
 
03. The most common initial-access attempts against the organization are macro-enabled Office documents arriving as email attachments from external senders.
Which control most directly prevents this specific vector?
a) Requiring TLS for inbound SMTP.
b) Reducing the lifetime of Kerberos service tickets issued in the domain.
c) A Group Policy that blocks macros in internet-originating Office files.
d) Enabling DNSSEC on the internal resolvers.
 
04. During threat modeling, the team finds that a shared operator account leaves no way to prove which individual performed a destructive administrative action, so any operator can plausibly deny responsibility.
Which STRIDE category does this threat represent, and what is the aligned mitigation?
a) Tampering, mitigated by integrity checks such as digital signatures on the data
b) Repudiation, mitigated by per-user accountability and tamper-evident logging
c) Information disclosure, mitigated by encrypting the administrative data at rest
d) Elevation of privilege, mitigated by enforcing least privilege on the account
 
05. Investigators suspect an implant is re-downloading and executing a payload through a built-in Windows transfer service that survives reboots, leaving little on disk. File antivirus has found nothing.
Which detection is most appropriate for this persistence?
a) Review the Background Intelligent Transfer Service logs for long-lived or unusual transfer jobs.
b) Rely on file-hash antivirus scanning of the download directory to find the payload written to disk.
c) Inspect the firmware for a bootkit implant.
d) Enumerate registry Run keys for autostart entries.
 
06. A defender identifies a newly installed kernel-mode driver configured to load early in the boot sequence and running with kernel privileges to hide the implant. This is not a firmware implant; it loads within the operating system.
Which control most directly prevents this class of persistence?
a) Reflash the UEFI firmware to a known-good image, since the implant lives below the operating system.
b) Enforce driver code-integrity to allow only signed, trusted drivers to load.
c) Rotate the KRBTGT password twice.
d) Deploy SPF, DKIM and DMARC on the mail domain.
 
07. Change monitoring flags that the Userinit value in the Winlogon registry key has been modified to append an extra executable that now runs at every interactive logon.
Which persistence mechanism is this, and what detects it?
a) A malicious Windows service, revealed by service-install event 7045.
b) A scheduled task, revealed by task-creation event 4698.
c) Winlogon Userinit or Shell modification.
d) A firmware bootkit that survives disk reimaging.
 
08. Users report an email that displays only a QR code image and asks them to scan it with a phone to re-validate their mailbox. The gateway's link-protection log recorded no URLs for the message.
Why did the mail-layer link controls fail to act on this lure?
a) Attachment detonation cleared the QR image because it contained no macros.
b) The message passed SPF, which certifies that any links it carries are safe.
c) DKIM signing exempts the message body from gateway inspection.
d) The malicious address is hidden inside an image, not a clickable link.
 
09. Most of the organization's recent phishing links point to domains that were registered only a few days earlier. A defender wants a web-layer control that reduces successful delivery even when the email itself slips past the mail gateway.
Which control most directly helps?
a) Web proxy filtering of newly-registered and low-reputation domains.
b) An outbound DLP rule applied to email.
c) Full-disk encryption on all endpoint devices.
d) Network segmentation between internal VLAN zones and server subnets.
 
10. After the organization blocked internet-originating macros, an incident shows users receiving a .lnk shortcut inside a ZIP archive. Opening the shortcut quietly launches a script interpreter that fetches the next stage.
Which delivery-stage control most directly reduces this vector?
a) Deploy DMARC in enforcement mode.
b) Enable the Antimalware Scan Interface so that scripts are inspected as they reach the scripting engine on the host.
c) Block shortcut and script file types such as .lnk, .hta, and .js at the mail gateway.
d) Rely on antivirus signatures for the shortcut file.

Answers:

Question: 01
Answer: d
Question: 02
Answer: a
Question: 03
Answer: c
Question: 04
Answer: b
Question: 05
Answer: a
Question: 06
Answer: b
Question: 07
Answer: c
Question: 08
Answer: d
Question: 09
Answer: a
Question: 10
Answer: c

Note: For any error in GIAC Defending Advanced Threats (GDAT) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 5 / 5 (74 votes)