
GIAC Red Team Professional
Domain 2Objective 1
Gaining Access GRTP Practice Questions (Page 6)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 26–30
- 26
A red team has compromised a standard user account in an Active Directory environment. The team wants to escalate to Domain Admin. The environment has a mature security posture with monitoring for unusual logon events and account lockouts. Which approach is most likely to succeed while minimizing detection?
Select an answer first - 27
Which of the following is a common initial access vector that involves tricking a user into opening a malicious attachment?
Select an answer first - 28
A red team is assessing a web application that is behind a Web Application Firewall (WAF). The team has identified a SQL injection vulnerability in a search parameter, but the WAF blocks common SQL injection payloads. The team wants to gain access to the backend database. Which approach is most likely to succeed?
Select an answer first - 29
A red team has gained access to a low-privileged domain account and wants to escalate privileges. The team discovers that the domain has a large number of users and that many accounts have not changed their passwords in years. Which technique is most likely to yield a higher-privileged account?
Select an answer first - 30
During discovery, which type of data would an attacker most likely prioritize for collection to prepare for exfiltration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.