
GIAC Penetration Tester (GPEN)
Domain 2Objective 1
Exploitation Fundamentals GPEN Practice Questions (Page 2)
Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
Questions 6–10
- 6
Which sequence correctly represents the typical exploitation lifecycle in a penetration test?
Select an answer first - 7
A penetration tester is using Metasploit to exploit a known vulnerability in a client's internal web server. The tester has already completed reconnaissance and identified the target service and version. The next step is to gain a foothold on the system. Which Metasploit component is specifically designed to deliver a payload to the target after a successful exploit?
Select an answer first - 8
A penetration tester is using Metasploit to exploit a vulnerable service on a Windows target. The tester has selected an exploit module and needs to configure the payload to establish a reverse TCP connection. Which Metasploit command is used to set the payload and its associated options?
Select an answer first - 9
A penetration tester has exploited a vulnerability and needs to maintain access to the target system. The tester wants to use a payload that establishes a persistent connection that reconnects automatically if the connection drops. Which type of payload is most suitable?
Select an answer first - 10
A penetration tester is using Metasploit to exploit a Windows server. The tester wants to migrate the Meterpreter session to a more stable process to avoid detection. Which command should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.