GIAC GDAT Exam Overview:
| Certification Vendor: | GIAC |
|---|---|
| Exam Name: | GIAC Defending Advanced Threats (GDAT) |
| Exam Number: | GDAT |
| Passing Score: | 70% |
| Certificate Validity Period: | 4 years |
| Exam Price: | $999 USD |
| Related Certifications: | SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses |
| Real Exam Qty: | 75 |
| Exam Format: | Multiple choice, Proctored |
| Exam Duration: | 120 minutes |
| Available Languages: | English |
| Recommended Training: | SANS SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses |
| Exam Registration: | Pearson VUE GIAC Official Registration |
| Sample Questions: | GIAC GDAT Sample Questions |
| Exam Way: | Web-based proctored exam; remote proctoring via ProctorU or onsite at Pearson VUE centers |
| Pre Condition: | No formal prerequisites; recommended training: SANS SEC599 |
| Official Syllabus URL: | https://www.giac.org/certifications/defending-advanced-threats-gdat |
GIAC GDAT Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Adversary Emulation | - Common tools - Technical controls - Basic concepts |
| Payload Delivery | - Defensive controls - Delivery methods |
| Application Exploitation | - Exploit mitigation techniques - Patch management - Software development lifecycle and threat modeling |
| Lateral Movement | - Movement techniques - Detection and prevention controls |
| Payload Execution | - Execution mechanisms - Detection and mitigation |
| Active Directory/Domains | - Authentication basics - Detecting attacks against domains - Kerberos protocol - Common attacks against domains |
| Reconnaissance, Threat Handling, and Incident Response | - Threat hunting - Reconnaissance methods - Incident response processes |
| Data Exfiltration | - Exfiltration strategies - Deception techniques - Command and control detection |
| Installation / Persistence | - Common persistence strategies - Protection mechanisms |
| Administrative Access | - Least privilege principles - Privilege escalation impacts |
GIAC Defending Advanced Threats Sample Questions:
What is the primary objective of using a drive-by download attack for payload delivery?
Response:
- A. To exploit browser vulnerabilities to install malware without user consent
- B. To conduct a denial-of-service (DoS) attack
- C. To trick users into providing sensitive information
- D. To monitor network traffic for anomalous behavior
Correct Answer: A 🗳️
In the context of exploit mitigation, what is the purpose of employing a Web Application Firewall (WAF)?
Response:
- A. To manage network bandwidth usage
- B. To detect and prevent SQL injection and cross-site scripting attacks
- C. To serve as the primary user authentication method
- D. To monitor network traffic
Correct Answer: B 🗳️
Which of the following are critical components of an effective incident response plan?
(Choose two)
Response:
- A. Root cause analysis
- B. Recovery
- C. Monitoring network latency
- D. Preparation
Correct Answer: B,D 🗳️
How can organizations protect against unauthorized persistence mechanisms?
Response:
- A. Restricting user permissions and access controls
- B. Regularly updating software and hardware
- C. Conducting annual security audits
- D. Monitoring network traffic for anomalies
Correct Answer: A 🗳️
How does implementing least privilege help mitigate security risks?
Response:
- A. It limits the impact of a compromised account.
- B. It reduces the need for regular security audits.
- C. It facilitates faster user onboarding.
- D. It increases the transparency of user actions.
Correct Answer: A,D 🗳️

We're so confident of our products that we provide no hassle product exchange.


By Odelette


