問題1
In the context of discovery, what is the purpose of a reverse DNS lookup?
Response:
In the context of discovery, what is the purpose of a reverse DNS lookup?
Response:
正確答案: D
問題2
When acquiring available credentials in a target environment, which methods are commonly used?
Multiple Correct Answers
Response:
When acquiring available credentials in a target environment, which methods are commonly used?
Multiple Correct Answers
Response:
正確答案: A,B,C
問題3
Which of the following is an essential component in building adversary infrastructure?
Response:
Which of the following is an essential component in building adversary infrastructure?
Response:
正確答案: D
問題4
In the context of privilege escalation on a Linux system, what is the significance of the SUID bit?
Response:
In the context of privilege escalation on a Linux system, what is the significance of the SUID bit?
Response:
正確答案: B
問題5
Which pieces of information are crucial when performing network discovery?
Multiple Correct Answers
Response:
Which pieces of information are crucial when performing network discovery?
Multiple Correct Answers
Response:
正確答案: A,B,D
問題6
Which of the following is a common method for delivering a payload to a target system?
Response:
Which of the following is a common method for delivering a payload to a target system?
Response:
正確答案: C
問題7
What is a common method to maintain persistence in a compromised system?
Response:
What is a common method to maintain persistence in a compromised system?
Response:
正確答案: D
問題8
What is the primary purpose of using a domain generation algorithm (DGA) in creating an attack infrastructure?
Response:
What is the primary purpose of using a domain generation algorithm (DGA) in creating an attack infrastructure?
Response:
正確答案: D
問題9
What is the purpose of performing Pass-the-Hash (PtH) attacks in a domain environment?
Response:
What is the purpose of performing Pass-the-Hash (PtH) attacks in a domain environment?
Response:
正確答案: D
問題10
What are two common techniques for data exfiltration in a red team engagement?
(Choose two)
Response:
What are two common techniques for data exfiltration in a red team engagement?
(Choose two)
Response:
正確答案: A,B
問題11
Which entities benefit the most from adversary emulation exercises?
Multiple Correct Answers
Response:
Which entities benefit the most from adversary emulation exercises?
Multiple Correct Answers
Response:
正確答案: A,C
問題12
During privilege escalation, which two indicators are commonly targeted by attackers?
(Choose two)
Response:
During privilege escalation, which two indicators are commonly targeted by attackers?
(Choose two)
Response:
正確答案: A,D
問題13
What is a primary use of a command and control (C2) server in a network intrusion?
Response:
What is a primary use of a command and control (C2) server in a network intrusion?
Response:
正確答案: D
問題14
In a C2 infrastructure, what role does the 'stager' play?
Response:
In a C2 infrastructure, what role does the 'stager' play?
Response:
正確答案: B
問題15
Which of the following attacks allows an attacker to impersonate a domain controller?
Response:
Which of the following attacks allows an attacker to impersonate a domain controller?
Response:
正確答案: D