
GIAC Penetration Tester (GPEN)
Domain 1Objective 2
Reconnaissance GPEN Practice Questions (Page 11)
Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 51–55
- 51
Which Nmap option is used for operating system fingerprinting?
Select an answer first - 52
You are conducting social engineering reconnaissance for a client. You need to identify key employees who might be targeted for phishing attacks, including their roles, email addresses, and potential personal interests. Which source is most likely to provide this information while remaining within passive reconnaissance?
Select an answer first - 53
You are planning the reconnaissance phase for a penetration test. The client has a strict security monitoring team that actively alerts on any unusual traffic. You need to gather as much information as possible while minimizing the risk of detection. Which combination of techniques is most appropriate?
Select an answer first - 54
What is the purpose of operating system fingerprinting?
Select an answer first - 55
Which tool is commonly used for network scanning to identify live hosts and open ports?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.