
GIAC Penetration Tester (GPEN)
Domain 2Objective 2
Escalation and Exploitation GPEN Practice Questions (Page 4)
Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 16–20
- 16
During a penetration test, you gain initial access to a Windows workstation as a standard domain user. You discover that the 'Vulnerable Service' runs with SYSTEM privileges and its executable path is writable by the Everyone group. You need to escalate privileges to SYSTEM. Which approach is most appropriate?
Select an answer first - 17
You have a Meterpreter session on a Windows workstation as a local admin. You need to move laterally to a file server, but you only have the NTLM hash of a domain user who has access to the file server. The target has SMB signing enforced. Which technique is most appropriate?
Select an answer first - 18
After compromising a Linux server, you need to maintain access and also clean up any traces of your activity. Which sequence of actions best follows a structured post-exploitation methodology?
Select an answer first - 19
Which lateral movement technique involves using captured password hashes to authenticate to other systems without knowing the plaintext password?
Select an answer first - 20
You have a low-privilege shell on a Linux system. You find that the 'docker' group is enabled for your user, and the Docker daemon is running. You need to escalate privileges to root. Which of the following is the most appropriate technique?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.