
GIAC Red Team Professional
Domain 2Objective 2
Discovery and Enumeration GRTP Practice Questions (Page 3)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 11–15
- 11
You are assessing a Google Cloud Platform (GCP) project for exposed services. You have read-only access to the project. Which enumeration step is most effective to identify firewall rules that allow public access to VM instances?
Select an answer first - 12
In the context of the attack lifecycle, what is the primary purpose of the discovery and enumeration phase?
Select an answer first - 13
Which tool is commonly used to discover hidden directories and files on a web server?
Select an answer first - 14
You are in the initial access phase of a red team engagement. You have a limited time window and need to identify the most promising target for further exploitation. Which combination of actions best supports this decision?
Select an answer first - 15
During a web application assessment, you need to discover hidden directories and parameters that are not linked from the main site. The application uses a JavaScript framework that loads content dynamically. Which approach is most effective for initial content discovery?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.