Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 2Objective 1

Exploitation Fundamentals GPEN Practice Questions (Page 4)

Part of the Exploitation and Post-Exploitation domain, which makes up ~22% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–26 in this domain), expect 4–7 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)

40questions here
8free pages
7concepts

Questions 16–20

  1. 16expert · hard

    A penetration tester is conducting an internal test and has gained a foothold on a Linux server. The tester needs to pivot to a Windows server on a different subnet. The Windows server is not directly reachable from the tester's workstation, but the Linux server can reach it. The tester wants to use Metasploit to exploit a vulnerability on the Windows server. What is the most effective way to proceed?

    Select an answer first
  2. 17expert · hard

    A penetration tester has gained a foothold on a web server and needs to move laterally to a database server. The database server is on a different subnet and is not directly reachable from the tester's attack machine. The web server has two network interfaces and can reach the database server. Which technique is most appropriate?

    Select an answer first
  3. 18foundation · easy

    A penetration tester discovers that a web application is vulnerable to SQL injection. Which action would be considered exploitation rather than vulnerability assessment?

    Select an answer first
  4. 19expert · hard

    A penetration tester has successfully exploited a web server and gained a reverse shell. The tester now needs to escalate privileges to obtain administrative access. The tester has identified a misconfigured service that runs with SYSTEM privileges. Which post-exploitation technique is most appropriate to escalate privileges?

    Select an answer first
  5. 20application · medium

    A penetration tester is assessing a web application that uses a backend database. During reconnaissance, the tester discovers that the application does not sanitize user input in a search field. The tester wants to demonstrate that this flaw can be exploited to retrieve unauthorized data. Which exploitation technique is the tester most likely to use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.