
GIAC Penetration Tester (GPEN)
Domain 1Objective 2
Reconnaissance GPEN Practice Questions (Page 8)
Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 57 practice questions to prepare you well beyond it. (estimate)
57questions here
12free pages
12concepts
Questions 36–40
- 36
During a penetration test, you are searching for sensitive information about a target organization that may have been inadvertently exposed in public documents. You have access to the company's website and general search engines. Which technique is most effective for discovering metadata that could reveal internal usernames, software versions, or network paths?
Select an answer first - 37
You are performing DNS enumeration for a target domain. The authoritative DNS server is configured to allow zone transfers only from specific IP addresses. You have also discovered that the domain uses a split-horizon DNS setup, where internal and external views differ. You need to enumerate internal hostnames without triggering a zone transfer. Which technique is most effective?
Select an answer first - 38
Which protocol does traceroute typically use to map the network path?
Select an answer first - 39
Which of the following is an example of an open-source intelligence (OSINT) source?
Select an answer first - 40
What is the purpose of performing DNS enumeration during reconnaissance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.