
GIAC Red Team Professional
Domain 2Objective 1
Gaining Access GRTP Practice Questions (Page 7)
Part of the Initial Access and Discovery domain, which makes up ~30% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~21–36 in this domain), expect 7–12 from this objective — we provide 47 practice questions to prepare you well beyond it. (estimate)
47questions here
10free pages
9concepts
Questions 31–35
- 31
An attacker calls a help desk employee, impersonates a remote worker, and requests a password reset. Which phishing method does this describe?
Select an answer first - 32
After compromising a Linux server in a DMZ, you need to identify other reachable hosts and services on the internal network without being detected by the security operations center (SOC). Which approach best balances stealth and effectiveness?
Select an answer first - 33
Which of the following is a technique used to gather detailed information about the operating system and installed software on a target host?
Select an answer first - 34
You have obtained a list of usernames from a public directory. The target organization uses a password policy that requires 12-character passwords with complexity. You want to test for weak passwords without causing account lockouts. Which method is most appropriate?
Select an answer first - 35
Which of the following is a common method for preparing data for exfiltration during the discovery phase?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GRTP” is a trademark of its owner, used for identification only.