
GIAC Penetration Tester (GPEN)
Domain 2Objective 4
Command and Control (C2) GPEN Practice Questions (Page 7)
Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)
35questions here
7free pages
7concepts
Questions 31–35
- 31
A penetration tester is using a C2 beacon that communicates over DNS. The client's security team has implemented a DNS sinkhole that blocks known malicious domains. The tester needs to maintain the C2 channel without being blocked. Which technique is most effective?
Select an answer first - 32
Which of the following is a core component of a Command and Control (C2) framework?
Select an answer first - 33
Which C2 module would an attacker use to move from one compromised host to another on the same network?
Select an answer first - 34
A penetration tester is running a C2 server for a long-term engagement. The tester wants to minimize the risk of the C2 server being taken down by the target's incident response team. Which operational security measure is most effective?
Select an answer first - 35
A penetration tester needs to deliver a C2 payload to a Windows 10 workstation that has Windows Defender enabled. The payload must execute in memory without writing to disk to avoid static detection. Which tool and technique combination is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to GPEN
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.