>_ CyberQuiz
← All rooms
🎯

Red Teaming

Adversary emulation: C2, lateral movement, credential theft, evasion and MITRE ATT&CK.

Hard 50 questions · 830 pts Room score: 0/830
Q1 Easy 10 pts

'C2' stands for:

Q2 Medium 15 pts

Moving from the initial compromised host to other systems is called lateral ____ .

Q3 Medium 15 pts

Mimikatz is most known for:

Q4 Medium 15 pts

Reusing a captured NTLM hash to authenticate without cracking it is Pass-the-____ .

Q5 Hard 20 pts

'Living off the land' (LOLBins) means:

Q6 Medium 15 pts

The MITRE ATT&CK tactic for stealing data OUT of the network is:

Q7 Hard 20 pts

Kerberoasting targets:

Q8 Hard 20 pts

AS-REP roasting works against accounts that:

Q9 Hard 20 pts

A 'Golden Ticket' attack forges:

Q10 Hard 20 pts

DCSync abuses replication rights to:

Q11 Medium 20 pts

BloodHound is used to:

Q12 Hard 20 pts

Pass-the-Ticket reuses:

Q13 Medium 15 pts

Cobalt Strike, Sliver and Mythic are:

Q14 Medium 15 pts

A C2 'beacon' typically:

Q15 Hard 20 pts

'Jitter' in a beacon is used to:

Q16 Hard 20 pts

AMSI bypass techniques aim to defeat:

Q17 Hard 20 pts

Process injection is used to:

Q18 Medium 15 pts

'Initial access' via a malicious document usually relies on:

Q19 Medium 15 pts

'MFA fatigue' (push bombing) attacks work by:

Q20 Hard 20 pts

A 'redirector' in C2 infrastructure:

Q21 Hard 20 pts

'Domain fronting' hides C2 traffic by:

Q22 Medium 15 pts

PsExec, WMI and WinRM are commonly used for:

Q23 Easy 10 pts

The offensive team is 'red'; the defenders monitoring/responding are the ____ team.

Q24 Medium 15 pts

'Purple teaming' means:

Q25 Medium 15 pts

An 'assumed breach' engagement starts from:

Q26 Hard 20 pts

IOAs (Indicators of Attack) differ from IOCs by focusing on:

Q27 Medium 15 pts

OPSEC for red teams means:

Q28 Medium 15 pts

Payload obfuscation/packing is used to:

Q29 Medium 15 pts

A 'reverse shell' beacon over HTTPS is preferred because:

Q30 Medium 15 pts

Data 'staging' before exfiltration means:

Q31 Medium 15 pts

Scheduled tasks and registry Run keys are examples of:

Q32 Hard 20 pts

A WMI event subscription is used by attackers for:

Q33 Hard 20 pts

'Token impersonation' on Windows lets an attacker:

Q34 Hard 20 pts

Unconstrained Kerberos delegation is dangerous because:

Q35 Medium 15 pts

The MITRE ATT&CK 'Defense Evasion' tactic covers:

Q36 Medium 15 pts

A red team's deliverable emphasizes:

Q37 Easy 10 pts

Phishing pretext quality matters because:

Q38 Hard 20 pts

C2 over DNS is useful when:

Q39 Hard 20 pts

'Silver Ticket' forges a ticket for:

Q40 Hard 20 pts

EDR evasion via 'unhooking' targets:

Q41 Medium 15 pts

Enumerating AD users/groups after a foothold is part of the ATT&CK tactic:

Q42 Medium 15 pts

A 'dropper' is malware that:

Q43 Hard 20 pts

Reflective DLL injection loads a DLL:

Q44 Medium 15 pts

Password spraying is favored over brute force in AD because it:

Q45 Easy 10 pts

A red team engagement should always have:

Q46 Easy 10 pts

Credential 'harvesting' via a cloned login portal is a form of:

Q47 Medium 15 pts

'Impact' tactic in ATT&CK includes:

Q48 Medium 15 pts

Detonating payloads in a lab before the op helps ensure:

Q49 Medium 20 pts

The main difference between a pentest and a red team op is:

Q50 Medium 15 pts

After the engagement, red teams should: