GIAC GDAT 시험 개요:
| 인증 벤더: | GIAC |
|---|---|
| 시험명: | GIAC 고급 위협 방어 (GDAT) |
| 시험 번호: | GDAT |
| 응시료: | $999 USD |
| 시험 형식: | 객관식, 감독 하 시행 |
| 시험 시간: | 120분 |
| 합격 점수: | 70% |
| 관련 자격증: | SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses |
| 실제 시험 문항 수: | 75 |
| 지원 언어: | English |
| 자격증 유효 기간: | 4년 |
| 권장 교육: | SANS SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses |
| 시험 등록: | GIAC 공식 등록 Pearson VUE |
| 샘플 문제: | GIAC GDAT 샘플 문제 |
| 응시 방법: | 웹 기반 감독 시행 방식; ProctorU를 통한 원격 감독 또는 Pearson VUE 시험 센터에서의 현장 감독 응시 가능 |
| 전제 조건: | 공식적인 응시 자격 요건은 없음; 권장 교육 과정: SANS SEC599 |
| 공식 요강 URL: | https://www.giac.org/certifications/defending-advanced-threats-gdat |
GIAC GDAT 시험 요강 주제:
| 섹션 | 목표 |
|---|---|
| 데이터 유출 | - 데이터 유출 전략 - 명령 및 제어 채널 탐지 - 기만 기법 |
| 페이로드 전달 | - 방어 통제 방안 - 전달 방식 |
| 측면 이동 | - 탐지 및 방지 통제 방안 - 이동 기법 |
| 페이로드 실행 | - 탐지 및 완화 방안 - 실행 메커니즘 |
| Adversary Emulation | - 기술적 통제 방안 - 주요 사용 도구 - 기본 개념 |
| 애플리케이션 익스플로잇 | - 소프트웨어 개발 수명 주기와 위협 모델링 - 패치 관리 - 익스플로잇 완화 기법 |
| 관리자 권한 접근 | - 최소 권한 원칙 - 권한 상승의 영향 |
| Active Directory/도메인 | - 도메인 공격 탐지 방안 - Kerberos 프로토콜 - 인증 기초 - 도메인에 대한 일반적인 공격 유형 |
| 정찰, 위협 대응 및 사고 대응 | - 사고 대응 절차 - 정찰 기법 - 위협 헌팅 |
| 설치 / 지속적 접근 | - 일반적인 지속적 접근 기법 - 방어 메커니즘 |
최신 GIAC Certification GDAT 무료샘플문제
문제 #1
Which of the following are indicators of a potential persistence attack?
(Choose Two)
Response:
A. Increased volume of outbound emails
B. Unexpected system shutdowns and restarts
C. Changes in system configuration files
D. Unexplained new user accounts on the system
문제 #2
Your security team has identified several instances where non-administrative users were able to escalate their privileges to gain administrative rights. Further investigation reveals that these users exploited a misconfiguration in group policies that inadvertently granted elevated access to all users in a specific department.
What are the next steps you should prioritize to remediate and prevent this issue?
Response:
A. Immediately disable administrative accounts on the affected machines
B. Conduct a privilege audit to identify and remove unnecessary elevated access
C. Implement role-based access control (RBAC) and enforce strict separation of duties
D. Reset all user passwords and enforce complex password policies
문제 #3
Which strategies help detect lateral movement in an enterprise environment?
(Choose Two)
Response:
A. Continuous monitoring of network traffic
B. Implementing strict password policies
C. Deploying intrusion detection systems (IDS)
D. Regular patching of software and systems
문제 #4
What role does the containment phase play in incident response?
Response:
A. It focuses on public relations management.
B. It ensures that the threat does not spread within the network.
C. It includes rolling out new software updates.
D. It involves negotiating with attackers.
문제 #5
Which of the following exemplifies a breach of the principle of least privilege?
(Choose two)
Response:
A. An HR intern is granted view-only access to personnel records for training purposes
B. An administrator is granted access to both production and testing environments
C. A database administrator has unrestricted access to a company's financial records
D. A sales associate has access to only customer information relevant to their region
질문과 대답:
| 문제 #1 정답: C,D | 문제 #2 정답: B,C | 문제 #3 정답: A,C | 문제 #4 정답: B | 문제 #5 정답: B,C |














986 개 고객 리뷰
품질과 가치ITCertKR 의 높은 정확도를 보장하는 최고품질의 덤프는 IT인증시험에 대비하여 제작된것으로서 높은 적중율을 자랑하고 있습니다.
테스트 및 승인ITCertKR 의 덤프는 모두 엘리트한 전문가들이 실제시험문제를 분석하여 답을 작성한 만큼 시험문제의 적중률은 아주 높습니다.
쉽게 시험패스ITCertKR의 테스트 엔진을 사용하여 시험을 준비한다는것은 첫 번째 시도에서 인증시험 패스성공을 의미합니다.
주문하기전 체험ITCertKR의 각 제품은 무료 데모를 제공합니다. 구입하기로 결정하기 전에 덤프샘플문제로 덤프품질과 실용성을 검증할수 있습니다.
