Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 1Objective 1

Penetration Test Planning GPEN Practice Questions (Page 3)

Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
7concepts

Questions 11–15

  1. 11expert · hard

    A multinational corporation with offices in multiple countries wants to test its global network. The corporation is subject to data residency laws that require certain data to remain in specific countries. The test will involve scanning and exploitation of systems in multiple regions. Which of the following is the most important consideration when defining the scope of the test?

    Select an answer first
  2. 12application · medium

    A healthcare organization wants to validate that its newly deployed internal EHR system is resistant to attacks from a malicious insider who has valid low-privileged domain credentials and knows the system's architecture from the vendor documentation. The organization wants the test to focus on what an authenticated user could access or escalate to, rather than on external discovery. Which testing approach and toolset best fits this requirement?

    Select an answer first
  3. 13application · medium

    A penetration tester is leading an engagement for a financial services client. The client has requested a test that focuses on the external perimeter and internal network segmentation. The tester has completed the reconnaissance phase and is about to begin scanning. Which sequence of actions best aligns with a structured penetration testing methodology?

    Select an answer first
  4. 14application · medium

    A penetration tester is engaged to assess a web application that uses a modern JavaScript framework with a REST API backend. The client has provided the application's source code and API documentation. The tester needs to identify vulnerabilities in the application's authentication and authorization logic. Which tool and technique combination is most appropriate for this task?

    Select an answer first
  5. 15foundation · easy

    During the scoping phase of a penetration test, the client states that the engagement must not include any social engineering attempts and must be limited to the IP range 192.168.10.0/24. Which document should explicitly capture these constraints before testing begins?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.