
GIAC Red Team Professional
Domain 2Objective 2
Discovery and Enumeration GRTP Practice Questions (Page 6)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
8concepts
Questions 26–30
- 26
You are enumerating a web application and notice that the server responds with different status codes for different paths (e.g., 200 for /admin, 403 for /admin/config). You need to determine which paths are accessible without authentication. Which technique is most effective?
Select an answer first - 27
Which statement best describes the difference between discovery and enumeration in the context of initial access?
Select an answer first - 28
What is the primary purpose of documenting enumeration findings during a red team engagement?
Select an answer first - 29
Which PowerShell cmdlet is used to query Active Directory for all user objects?
Select an answer first - 30
You have obtained a low-privileged domain user account in an Active Directory environment. Your objective is to identify potential privilege escalation paths by discovering domain admins, their group memberships, and any accounts with 'Do not require Kerberos pre-authentication' enabled. Which approach is most efficient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.