Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC Penetration Tester (GPEN)

Domain 1Objective 4

Vulnerability Scanning GPEN Practice Questions (Page 1)

Part of the Penetration Testing Foundations domain, which makes up ~24% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 180-minute exam (~70–120 total, ~17–29 in this domain), expect 4–7 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
6concepts

Questions 1–5

  1. 1foundation · easy

    When configuring a vulnerability scan, what is the purpose of setting a scan policy?

    Select an answer first
  2. 2application · medium

    A vulnerability scan report lists a 'High' severity finding for a service that is no longer in use and has been disabled on the target system. The tester confirms that the service is disabled and not reachable. How should the tester handle this finding in the final report?

    Select an answer first
  3. 3foundation · easy

    What is a key limitation of vulnerability scanning that a penetration tester must consider when interpreting scan results?

    Select an answer first
  4. 4foundation · easy

    What is a key characteristic of an effective vulnerability scan report?

    Select an answer first
  5. 5foundation · easy

    Why is it important to schedule vulnerability scans during maintenance windows or off-peak hours?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GPEN” is a trademark of its owner, used for identification only.