
GIAC Red Team Professional
Domain 1Objective 1
Adversary Emulation Fundamentals GRTP Practice Questions (Page 4)
Part of the Red Team Operations and Infrastructure domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~27–46 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 16–20
- 16
Which framework is commonly used to categorize an adversary's tactics, techniques, and procedures in a structured, knowledge-base format?
Select an answer first - 17
During an adversary emulation exercise, the red team is replicating a threat group that uses a specific remote access tool (RAT) and a particular command-and-control (C2) protocol. The team has deployed the RAT and established C2. Which action best aligns with the emulation plan?
Select an answer first - 18
What is the primary purpose of evaluating detection and response capabilities during adversary emulation?
Select an answer first - 19
How does threat intelligence primarily inform adversary emulation planning?
Select an answer first - 20
A company is planning an adversary emulation exercise and has limited budget. The threat intelligence indicates that the threat group has multiple TTPs, but the company wants to focus on the most likely attack path. The red team has identified three potential attack paths, each with different levels of likelihood and impact. Which approach best uses threat modeling to prioritize the exercise?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.