
GIAC Red Team Professional
Domain 2Objective 1
Gaining Access GRTP Practice Questions (Page 3)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 11–15
- 11
During network enumeration, what does a TCP connect scan (e.g., nmap -sT) do?
Select an answer first - 12
A red team is targeting a company that has recently implemented a security awareness program and enforced MFA for all external logins. The team has a limited budget and cannot use zero-day exploits. The company uses Office 365 and has a public-facing VPN portal. Which combination of techniques is most likely to achieve initial access?
Select an answer first - 13
A red team is tasked with gaining initial access to a company that has strong endpoint protection and email filtering. The company uses multi-factor authentication (MFA) for all remote access. Which initial access vector is most likely to succeed despite these controls?
Select an answer first - 14
During a red team exercise, you have gained access to a web server. You need to identify installed software and services that could be exploited for lateral movement. Which enumeration step is most likely to reveal exploitable services?
Select an answer first - 15
After gaining initial access, which discovery technique would an attacker use to identify other systems on the same network segment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.