
GIAC Penetration Tester (GPEN)
Domain 2Objective 2
Escalation and Exploitation GPEN Practice Questions (Page 6)
Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
8concepts
Questions 26–30
- 26
You have a low-privilege shell on a Windows server. You discover that the 'MSSQLSERVER' service runs as SYSTEM and is configured with 'xp_cmdshell' enabled. You have access to the SQL Server with 'sa' credentials. Which action is most appropriate to escalate privileges?
Select an answer first - 27
During a penetration test, an attacker gains access to a standard user account on a Windows workstation and then exploits a misconfigured service to obtain SYSTEM privileges. Which type of privilege escalation does this describe?
Select an answer first - 28
You have captured an NTLM hash of a domain admin from a compromised workstation. You need to access a file server using that hash without cracking it. Which technique should you use?
Select an answer first - 29
You have a low-privilege shell on a Windows server. You discover that the 'Spooler' service is running and vulnerable to a known privilege escalation exploit. Which action is most appropriate?
Select an answer first - 30
You have a low-privilege shell on a Linux server. You find a cron job that runs a script as root every minute. The script is writable by your user. However, the script is executed via a relative path from the cron job's working directory. You need to escalate to root without disrupting the cron job's normal function. Which action is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.