Q1
Easy
10 pts
Red Teaming
Adversary emulation: C2, lateral movement, credential theft, evasion and MITRE ATT&CK.
Q2
Medium
15 pts
Moving from the initial compromised host to other systems is called lateral ____ .
Q3
Medium
15 pts
Mimikatz is most known for:
Q4
Medium
15 pts
Reusing a captured NTLM hash to authenticate without cracking it is Pass-the-____ .
Q5
Hard
20 pts
'Living off the land' (LOLBins) means:
Q6
Medium
15 pts
The MITRE ATT&CK tactic for stealing data OUT of the network is:
Q7
Hard
20 pts
Kerberoasting targets:
Q8
Hard
20 pts
AS-REP roasting works against accounts that:
Q9
Hard
20 pts
A 'Golden Ticket' attack forges:
Q10
Hard
20 pts
DCSync abuses replication rights to:
Q11
Medium
20 pts
BloodHound is used to:
Q12
Hard
20 pts
Pass-the-Ticket reuses:
Q13
Medium
15 pts
Cobalt Strike, Sliver and Mythic are:
Q14
Medium
15 pts
A C2 'beacon' typically:
Q15
Hard
20 pts
'Jitter' in a beacon is used to:
Q16
Hard
20 pts
AMSI bypass techniques aim to defeat:
Q17
Hard
20 pts
Process injection is used to:
Q18
Medium
15 pts
'Initial access' via a malicious document usually relies on:
Q19
Medium
15 pts
'MFA fatigue' (push bombing) attacks work by:
Q20
Hard
20 pts
A 'redirector' in C2 infrastructure:
Q21
Hard
20 pts
'Domain fronting' hides C2 traffic by:
Q22
Medium
15 pts
PsExec, WMI and WinRM are commonly used for:
Q23
Easy
10 pts
The offensive team is 'red'; the defenders monitoring/responding are the ____ team.
Q24
Medium
15 pts
'Purple teaming' means:
Q25
Medium
15 pts
An 'assumed breach' engagement starts from:
Q26
Hard
20 pts
IOAs (Indicators of Attack) differ from IOCs by focusing on:
Q27
Medium
15 pts
OPSEC for red teams means:
Q28
Medium
15 pts
Payload obfuscation/packing is used to:
Q29
Medium
15 pts
A 'reverse shell' beacon over HTTPS is preferred because:
Q30
Medium
15 pts
Data 'staging' before exfiltration means:
Q31
Medium
15 pts
Scheduled tasks and registry Run keys are examples of:
Q32
Hard
20 pts
A WMI event subscription is used by attackers for:
Q33
Hard
20 pts
'Token impersonation' on Windows lets an attacker:
Q34
Hard
20 pts
Unconstrained Kerberos delegation is dangerous because:
Q35
Medium
15 pts
The MITRE ATT&CK 'Defense Evasion' tactic covers:
Q36
Medium
15 pts
A red team's deliverable emphasizes:
Q37
Easy
10 pts
Phishing pretext quality matters because:
Q38
Hard
20 pts
C2 over DNS is useful when:
Q39
Hard
20 pts
'Silver Ticket' forges a ticket for:
Q40
Hard
20 pts
EDR evasion via 'unhooking' targets:
Q41
Medium
15 pts
Enumerating AD users/groups after a foothold is part of the ATT&CK tactic:
Q42
Medium
15 pts
A 'dropper' is malware that:
Q43
Hard
20 pts
Reflective DLL injection loads a DLL:
Q44
Medium
15 pts
Password spraying is favored over brute force in AD because it:
Q45
Easy
10 pts
A red team engagement should always have:
Q46
Easy
10 pts
Credential 'harvesting' via a cloned login portal is a form of:
Q47
Medium
15 pts
'Impact' tactic in ATT&CK includes:
Q48
Medium
15 pts
Detonating payloads in a lab before the op helps ensure:
Q49
Medium
20 pts
The main difference between a pentest and a red team op is:
Q50
Medium
15 pts