
GIAC Red Team Professional
Domain 1Objective 1
Adversary Emulation Fundamentals GRTP Practice Questions (Page 5)
Part of the Red Team Operations and Infrastructure domain, which makes up ~38% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~27–46 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
7concepts
Questions 21–25
- 21
What is the primary purpose of defining rules of engagement (ROE) in an adversary emulation engagement?
Select an answer first - 22
During an emulation, the red team needs to deploy a tool that mimics the command and control (C2) communication of a specific malware family. The team has a sandbox environment that replicates the production network. What should they do to ensure the emulation is effective?
Select an answer first - 23
A company wants to emulate a threat actor that is known to target the energy sector. The team has limited intelligence about the actor's specific tools but knows their preferred entry points and objectives. How should the team approach the emulation?
Select an answer first - 24
After completing an adversary emulation exercise, the red team has compiled a list of findings, including which techniques were detected, which were missed, and the overall effectiveness of the SOC. What is the most important next step to ensure the exercise leads to improvement?
Select an answer first - 25
How should lessons learned from an adversary emulation exercise be incorporated into an organization's security program?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.