
GIAC Red Team Professional
Domain 2Objective 1
Gaining Access GRTP Practice Questions (Page 4)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 16–20
- 16
A red team has gained access to a Windows server that runs a legacy application. The team wants to identify installed software and services that may have known vulnerabilities. Which method is most appropriate?
Select an answer first - 17
A red teamer wants to phish a high-level executive who frequently posts on LinkedIn about industry events. The goal is to obtain the executive's credentials without triggering email security filters. Which phishing technique is most appropriate?
Select an answer first - 18
You have compromised a file server that contains sensitive project documents. Your objective is to exfiltrate data without being detected by data loss prevention (DLP) systems that monitor outbound traffic. Which approach is most likely to avoid detection?
Select an answer first - 19
An attacker exploits a SQL injection vulnerability in a public-facing web application to gain a foothold. Which initial access vector category does this represent?
Select an answer first - 20
A red teamer wants to phish a group of employees in the finance department. The team has obtained a list of their email addresses and knows they frequently use a specific internal expense reporting system. Which phishing technique is most likely to succeed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.