Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 1Objective 2

Reconnaissance GPEN Practice Questions (Page 2)

Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)

57questions here
12free pages
12concepts

Questions 6–10

  1. 6application · medium

    You are conducting an authorized penetration test against a target network. You need to identify live hosts, open ports, and the operating systems of the discovered hosts. The client has requested minimal network disruption and wants to avoid crashing any services. Which Nmap scan type is most appropriate for this phase?

    Select an answer first
  2. 7expert · hard

    You are mapping a target network that uses a load balancer in front of multiple web servers. You need to identify the individual servers behind the load balancer. Which technique is most effective?

    Select an answer first
  3. 8application · medium

    You are performing reconnaissance on a client's domain. You have found that the DNS server allows zone transfers. You want to use this to gather a comprehensive list of hostnames and IP addresses. Which technique is most appropriate?

    Select an answer first
  4. 9expert · hard

    You are leading a penetration test for a client that is highly concerned about data leakage. The client has asked you to identify any sensitive information that is publicly accessible, but they have also instructed you to avoid any technique that could be considered intrusive or that might alert their security team. You have a limited time window and need to prioritize your efforts. Which approach best balances thoroughness with the client's constraints?

    Select an answer first
  5. 10expert · hard

    You are performing OSINT for a client. You have found a PDF document on their website that contains metadata with the author's username 'jdoe' and the software 'Microsoft Word 2016'. You also found a LinkedIn profile for a 'John Doe' who works at the company. Which additional step would most effectively leverage this information for a social engineering attack?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.